CVE-2026-32287: Antchfx Xpath

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

Boolean XPath expressions that evaluate to true can cause an infinite loop in logicalQuery.Select, leading to 100% CPU usage. This can be triggered by top-level selectors such as "1=1" or "true()".

Affected products

  • Antchfx Xpath: before 1.3.6 (fixed in 1.3.6)

Published 2026-03-26. Last modified 2026-06-17.