CVE-2026-7210

Aliases:ALPINE-CVE-2026-7210UBUNTU-CVE-2026-7210DEBIAN-CVE-2026-7210CGA-4h64-mv2w-5hppCGA-4jp4-99xm-3q68CGA-4wm6-gw95-xqv3CGA-6g24-ph8m-vj9mCGA-f2xq-5g85-fcv8CGA-fgg5-525j-xp8pCGA-gfww-cv55-vrm9CGA-mp75-hrgp-9999CGA-rgc2-288h-x4jpCGA-w82v-p6qf-2wr9
Modified
Published: 11 May 2026, 17:19
Last modified:14 Aug 2026, 00:28

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (nvd)
EPSS Score
0.67% LOW
1% probability -0.12%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

11 May 2026, 17:19
Published
Vulnerability first disclosed
14 Aug 2026, 00:28
Last Modified
Vulnerability information updated

Description

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

CVSS Metrics

  • v4.0MEDIUMScore: 6.3CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
  • v4.0MEDIUMScore: 6.3CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.67% Percentile: 51%

Techniques & Countermeasures

  • CWE-331Insufficient Entropy

    The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.

Affected Systems

  • alpinepython3

    < 3.12.14-r0 | < 3.12.14-r0 | < 3.12.14-r0 | < 3.14.7-r0

  • chainguardpython-3.10

    all

  • chainguardpython-3.11

    all | < 3.11.16-r7

  • chainguardpython-3.12

    all | < 3.12.14-r8

  • chainguardpython-3.13

    < 3.13.14-r0

  • chainguardpython-3.14

    < 3.14.6-r1

  • wolfipython-3.10

    all

  • wolfipython-3.11

    all | < 3.11.16-r7

  • wolfipython-3.12

    all | < 3.12.14-r8

  • wolfipython-3.13

    < 3.13.14-r0

  • wolfipython-3.14

    < 3.14.6-r1

  • debianpython2.7

    all

  • debianpython3.11

    all

  • debianpython3.13

    all | < 3.13.14-1

  • debianpython3.14

    < 3.14.6-1

  • debianpython3.9

    all

  • ubuntupython2.7

    all

  • ubuntupython3.10

    all

  • ubuntupython3.11

    all | all

  • ubuntupython3.12

    all

  • ubuntupython3.13

    all

  • ubuntupython3.14

    all | all

  • ubuntupython3.4

    all

  • ubuntupython3.5

    all

  • ubuntupython3.6

    all

  • ubuntupython3.7

    all

  • ubuntupython3.8

    all

  • ubuntupython3.9

    all

  • libexpat_projectlibexpat

    < 2.8.0

  • python software foundationcpython

    < 3.15.0 | < 3.13.14 | < 3.11.16 | ≥ 3.12.0, < 3.12.14 | ≥ 3.13.0, < 3.13.14 | ≥ 3.14.0, < 3.14.6 | ≥ 3.15.0a1, < 3.15.0b2

  • pythonpython

    < 3.15.0 | < 3.13.14 | ≥ 3.14.0, < 3.14.6 | 3.15.0:alpha1 | 3.15.0:alpha2 | 3.15.0:alpha3 | 3.15.0:alpha4 | 3.15.0:alpha5 | 3.15.0:alpha6 | 3.15.0:alpha7 | 3.15.0:alpha8 | 3.15.0:beta1

References (19)