CVE Vulnerabilities

CVE-2026-7210

Insufficient Entropy

Published: May 11, 2026 | Modified: Jun 15, 2026
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

xml.parsers.expat and xml.etree.ElementTree use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.rnrnFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

Weakness

The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.

Affected Software

NameVendorStart VersionEnd Version
PythonPython*3.15.0 (excluding)
Python2.7Ubuntuesm-infra/xenial*
Python3.13Ubuntuupstream*
Python3.14Ubuntudevel*
Python3.14Ubuntuupstream*
Python3.5Ubuntuesm-infra/xenial*

Potential Mitigations

References