CVE-2026-32287 details a denial-of-service vulnerability where Boolean XPath expressions evaluating to true can cause an infinite loop in logicalQuery.Select, leading to 100% CPU usage; affected products are not specified in the provided data. Rated with a high CVSS score of 7.5, this vulnerability is remotely exploitable over the network with low complexity, requiring no privileges or user interaction, and primarily impacts system availability. There is no evidence of active exploitation, nor is public exploit code available, though the vulnerability has received minimal community discussion and a security update from SUSE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3.6CPE matchmatch criteria | cpe:2.3:a:antchfx:xpath:*:*:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.