7.5

CVE-2026-7210

The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Python ≫ Python Version < 3.13.14
Python ≫ Python Version >= 3.14.0 < 3.14.6
Python ≫ Python Version 3.15.0 Update alpha1
Python ≫ Python Version 3.15.0 Update alpha2
Python ≫ Python Version 3.15.0 Update alpha3
Python ≫ Python Version 3.15.0 Update alpha4
Python ≫ Python Version 3.15.0 Update alpha5
Python ≫ Python Version 3.15.0 Update alpha6
Python ≫ Python Version 3.15.0 Update alpha7
Python ≫ Python Version 3.15.0 Update alpha8
Python ≫ Python Version 3.15.0 Update beta1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.81% 0.537
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
cna@python.org 6.3 0 0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-331 Insufficient Entropy

The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.

https://github.com/python/cpython/issues/149018
Issue Tracking
https://github.com/python/cpython/pull/149023
Patch
Issue Tracking
http://www.openwall.com/lists/oss-security/2026/05/11/8
Third Party Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/11/13
Third Party Advisory
Mailing List
https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4
Patch
https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566
Patch
https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a
Patch
https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f
Patch
https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/
Third Party Advisory
Mailing List
https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b
https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56
https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286