CVE-2026-32287High· 7.5▾ TwilightXPath: Boolean expression infinite loop leads to denial of service via CPU exhaustion
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.5%
Boolean expressions that evaluate to true can cause an infinite loop in logicalQuery.Select, leading to 100% CPU usage. This can be triggered by top-level selectors such as "1=1" or "true()".
github.com/antchfx/xpath < 1.3.6Upgrade to a patched release:
github.com/antchfx/xpath 1.3.6