Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-7210

32
FAUCET Score

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

First published: May 11, 2026Last modified: Jun 10, 2026

Impacted Technologies

VendorProductVersion(s)CPE
< 3.15.0CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 0, < 3.13.14CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.14.0, < 3.14.6CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

6.3MEDIUM

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.79%
Probability of exploitation in next 30 days
EPSS Percentile
52.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0079 is in the 28th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

github_advisorypatch availablevia nvd_reference
View patch
ubuntupatch availablevia ubuntu_usn
Product: python2.7 (xenial)Fixed in: 2.7.12-1ubuntu0~16.04.18+esm20
ubuntupatch availablevia ubuntu_usn
Product: python3.5 (xenial)Fixed in: 3.5.2-2ubuntu0~16.04.13+esm23

Vendor Advisories (2)

ubuntuUSN-8524-1

Python vulnerability

Jul 9, 2026
microsoft2026-May/CVE-2026-7210Low

The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection

May 12, 2026

References

openwall.com / lists/oss-security/2026/05/11/13
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2026/05/11/8
Mailing ListThird Party Advisory
github.com / python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4
Patch
github.com / python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566
Patch
github.com / python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a
Patch
github.com / python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f
Patch
github.com / python/cpython/issues/149018
Issue Tracking
github.com / python/cpython/pull/149023
Issue TrackingPatch
mail.python.org / archives/list/[email protected]/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K
Mailing ListThird Party Advisory