CVE-2026-4224High· 7.5▾ TwilightWhen an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 5.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.6%
0.6% → 0.7%
When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.
python < 3.10.0python >= 3.13.0, < 3.13.13python >= 3.14.0, < 3.14.4python = 3.15.0Upgrade past the affected range:
python 3.14.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-4519Low· 3.3The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers
CVE-2026-7210High· 7.5`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating …
CVE-2026-44432High· 7.5urllib3 is an HTTP client library for Python
CVE-2025-48379High· 7.1Pillow is a Python imaging library
CVE-2026-40192High· 7.5Pillow is a Python imaging library
CVE-2026-25990High· 7.5Pillow is a Python imaging library