oss-sec mailing list archives

Re: [oss-security][CVE-2026-7210] Cpython: The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection


From: Sebastian Pipping <sebastian () pipping org>
Date: Mon, 11 May 2026 21:05:24 +0200

On 5/11/26 19:20, Alan Coopersmith wrote:
Fully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

This sentence ^^ deserves additional highlight. I confirm.


Current thread: