CVE-2026-92987: Razrfalcon Roxmltree

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

roxmltree through 0.21.1 performs quadratic-time attribute and namespace validation during XML parsing without limits on attribute count. Attackers can craft XML documents with tens of thousands of attributes on a single element to consume excessive CPU time and cause denial of service.

Affected products

Published 2026-09-17. Last modified 2026-09-22.