{"id":"CVE-2026-7210","title":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating …","summary":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating …","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-331"],"vendor":"python","product":"python","affected":["python < 3.13.14","python >= 3.14.0, < 3.14.6","python = 3.15.0"],"patched":["python 3.14.6"],"published":"2026-05-11","updated":"2026-07-27","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","references":[{"url":"https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","label":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","label":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","label":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","label":"cna@python.org"},{"url":"https://github.com/python/cpython/issues/149018","label":"cna@python.org"},{"url":"https://github.com/python/cpython/pull/149023","label":"cna@python.org"},{"url":"https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","label":"cna@python.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/05/11/13","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2026/05/11/8","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7210.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-7210"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2469216"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-7210"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210"},{"url":"https://access.redhat.com/errata/RHSA-2026:67572"},{"url":"https://access.redhat.com/errata/RHSA-2026:69069"},{"url":"https://access.redhat.com/errata/RHSA-2026:68135"},{"url":"https://access.redhat.com/errata/RHSA-2026:68154"},{"url":"https://access.redhat.com/errata/RHSA-2026:68309"}],"tags":["nvd","csaf","vex","red-hat","score-dispute"],"epss":0.00672,"epssPercentile":0.50608,"ingestedAt":"2026-07-27T18:22:58.198Z","scores":{"nvd":7.5,"vendor":5.3},"slug":"CVE-2026-7210","body":"## Overview\n\n`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.\n\n## Affected\n\n- `python < 3.13.14`\n- `python >= 3.14.0, < 3.14.6`\n- `python = 3.15.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `python 3.14.6`\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Exploit Intelligence, Red Hat AI Inference Server, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, … · no fix planned: Exploit Intelligence, Red Hat AI Inference Server, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7210.json)\n- **RHSA-2026:67572** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67572)\n- **RHSA-2026:69069** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:69069)\n- **RHSA-2026:68135** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68135)\n- **RHSA-2026:68154** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68154)\n- **RHSA-2026:68309** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68309)","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}