CVE-2026-4224

Aliases:UBUNTU-CVE-2026-4224DEBIAN-CVE-2026-4224ALPINE-CVE-2026-4224CGA-2cjc-h55h-4h7hCGA-2f3w-7jc7-vvjqCGA-5ch6-mfr3-xw68CGA-75wj-5wm7-mgqqCGA-g75c-f9wm-ccj8CGA-ghrg-q8g4-qmx3CGA-mv5w-r44x-pph4CGA-pvp9-hxgx-9m75CGA-fw6p-3cf8-2m3cCGA-fw77-6gq7-q79jCGA-rr8h-v3r3-xj5cCGA-v86f-hjgr-j355
Modified
Published: 16 Mar 2026, 17:52
Last modified:13 Aug 2026, 00:27

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (nvd)
EPSS Score
0.69% LOW
1% probability +0.60%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

16 Mar 2026, 17:52
Published
Vulnerability first disclosed
13 Aug 2026, 00:27
Last Modified
Vulnerability information updated

Description

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.

CVSS Metrics

  • v4.0MEDIUMScore: 6CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  • v4.0MEDIUMScore: 6CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.69% Percentile: 51%

Techniques & Countermeasures

  • CWE-674Uncontrolled Recursion

    The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Affected Systems

  • alpinepython3

    < 3.14.5-r0

  • chainguardpython-3.10

    all | < 3.10.21-r6

  • chainguardpython-3.11

    < 3.11.15-r9

  • chainguardpython-3.12

    all | < 3.12.14-r8

  • chainguardpython-3.13

    < 3.13.12-r7

  • chainguardpython-3.14

    < 3.14.3-r6

  • chainguardpython-3.9

    all

  • wolfipython-3.10

    all | < 3.10.21-r6

  • wolfipython-3.11

    < 3.11.15-r9

  • wolfipython-3.12

    all | < 3.12.14-r8

  • wolfipython-3.13

    < 3.13.12-r7

  • wolfipython-3.14

    < 3.14.3-r6

  • debianpython2.7

    all

  • debianpython3.11

    < 3.11.2-6+deb12u8

  • debianpython3.13

    < 3.13.5-2+deb13u2 | < 3.13.14-1

  • debianpython3.14

    < 3.14.3-4

  • debianpython3.9

    < 3.9.2-1+deb11u7

  • ubuntupypy3

    all | all | all | all | all

  • ubuntupython2.7

    all | < 2.7.6-8ubuntu0.6+esm30 | < 2.7.12-1ubuntu0~16.04.18+esm22 | < 2.7.17-1~18.04ubuntu1.13+esm15 | < 2.7.18-13ubuntu1.5+esm9

  • ubuntupython3.10

    < 3.10.12-1~22.04.16

  • ubuntupython3.11

    all | all | < 3.11.0~rc1-1~22.04.1+esm2

  • ubuntupython3.12

    < 3.12.3-1ubuntu0.15

  • ubuntupython3.13

    all

  • ubuntupython3.14

    all

  • ubuntupython3.4

    all | < 3.4.3-1ubuntu1~14.04.7+esm21

  • ubuntupython3.5

    all | < 3.5.2-2ubuntu0~16.04.4~14.04.1+esm11 | < 3.5.2-2ubuntu0~16.04.13+esm25

  • ubuntupython3.6

    all | < 3.6.9-1~18.04ubuntu1.13+esm10

  • ubuntupython3.7

    all | < 3.7.5-2ubuntu1~18.04.2+esm11

  • ubuntupython3.8

    all | < 3.8.0-3ubuntu1~18.04.2+esm11 | < 3.8.10-0ubuntu1~20.04.18+esm7

  • ubuntupython3.9

    all | < 3.9.5-3ubuntu0~20.04.1+esm11

  • python software foundationcpython

    < 3.15.0 | < 3.14.4 | < 3.13.13 | < 3.10.21 | ≥ 3.11.0, < 3.11.16 | ≥ 3.12.0, < 3.12.14 | ≥ 3.13.0, < 3.13.13 | ≥ 3.14.0, < 3.14.4 | ≥ 3.15.0a1, < 3.15.0a8

  • pythonpython

    < 3.10.0 | ≥ 3.13.0, < 3.13.13 | ≥ 3.14.0, < 3.14.4 | 3.15.0:alpha1 | 3.15.0:alpha2 | 3.15.0:alpha3 | 3.15.0:alpha4 | 3.15.0:alpha5 | 3.15.0:alpha6 | 3.15.0:alpha7

References (19)