CVE-2026-7210: Python

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

Affected products

  • Python Python: before 3.13.14 (fixed in 3.13.14); from 3.14.0, before 3.14.6 (fixed in 3.14.6); version 3.15.0 only

Published 2026-05-11. Last modified 2026-10-02.