CVE-2026-4224 identifies a C stack overflow vulnerability within the Expat XML parser, triggered by processing deeply nested inline document type definitions. While no specific affected products are officially listed, applications using the Expat library could be susceptible. Rated Medium severity (CVSS 6.0), this issue allows a remote attacker with low privileges to cause a denial of service with low complexity and no user interaction. There is currently no evidence of active exploitation, public exploit code, or significant community attention, with a very low EPSS score reflecting its low exploitability probability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 3.15.0CPE match | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
< 3.10.0CPE matchmatch criteria | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
>= 3.13.0, < 3.13.13CPE matchmatch criteria | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
>= 3.14.0, < 3.14.4CPE matchmatch criteria | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
3.15.0CPE matchmatch criteria | cpe:2.3:a:python:python:3.15.0:alpha1:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.