CVE Vulnerabilities

CVE-2026-4224

Uncontrolled Recursion

Published: Mar 16, 2026 | Modified: Jun 04, 2026
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
5.9 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.

Weakness

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Affected Software

NameVendorStart VersionEnd Version
PythonPython*3.10.0 (excluding)
PythonPython3.13.0 (including)3.13.13 (excluding)
PythonPython3.14.0 (including)3.14.4 (excluding)
PythonPython3.15.0-alpha1 (including)3.15.0-alpha1 (including)
PythonPython3.15.0-alpha2 (including)3.15.0-alpha2 (including)
PythonPython3.15.0-alpha3 (including)3.15.0-alpha3 (including)
PythonPython3.15.0-alpha4 (including)3.15.0-alpha4 (including)
PythonPython3.15.0-alpha5 (including)3.15.0-alpha5 (including)
PythonPython3.15.0-alpha6 (including)3.15.0-alpha6 (including)
PythonPython3.15.0-alpha7 (including)3.15.0-alpha7 (including)
Red Hat Enterprise Linux 10RedHatpython3.14-0:3.14.4-2.el10_2*
Red Hat Enterprise Linux 10RedHatpython3.12-0:3.12.13-2.el10_2*
Red Hat Enterprise Linux 8RedHatpython3.12-0:3.12.13-2.el8_10*
Red Hat Enterprise Linux 9RedHatpython3.14-0:3.14.4-2.el9_8*
Red Hat Enterprise Linux 9RedHatpython3.12-0:3.12.13-2.el9_8*
Red Hat Hardened ImagesRedHatpython3-13-main-3.13.13-1.hum1*
Red Hat Hardened ImagesRedHatpython3-14-main-3.14.4-1.hum1*
Red Hat Hardened ImagesRedHatpython3-11-main-3.11.15-4.hum1*
Red Hat Hardened ImagesRedHatpython3-12-main-3.12.13-3.hum1*
Red Hat Update Infrastructure 5RedHatrhui5/installer-rhel9:1779798165*
Red Hat Update Infrastructure 5RedHatrhui5/rhua-rhel9:1779798222*
Python2.7Ubuntuesm-infra/xenial*
Python3.13Ubuntuupstream*
Python3.14Ubuntuupstream*
Python3.5Ubuntuesm-infra/xenial*

Potential Mitigations

References