CVE Tracker

CVE-2026-4224 @ Library

Status
accepted_risk
Priority
1.75
Match score
4.0
Risk
DoS Remote
CVSS
7.5 HIGH
Reason
cpe: python; pkgs: python, python-crypto, python-dnspython, python-ldb, python-minimal, python-samba; version: in-range: python-stdlib-2.7.13-2, python-2.7.13-2, python-crypto-2.6.1-7, python-dnspython-1.15.0-1+deb9u1, python-ldb-1.1.27-1+deb9u2, python-minimal-2.7.13-2; risk:dos
Created
2026-08-05T14:05:15Z
Updated
2026-08-22T10:15:58Z
Closed
2026-08-05T14:46:21Z

Package interrogation (copy)

Run on the host — click to copy a command. Debian/apt

PackageCommands
python-stdlib-2.7.13-2
python-2.7.13-2
python-crypto-2.6.1-7
python-dnspython-1.15.0-1+deb9u1
python-ldb-1.1.27-1+deb9u2
python-minimal-2.7.13-2
python-samba

Inventory lookup

Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.

Clear

Suggestions: python-stdlib · python · python-crypto · python-dnspython · python-ldb · python-minimal · python-samba

SystemMatchesTicket for CVE-2026-4224
Archive libpython-stdlib 2.7.16-1; libpython2-stdlib 2.7.16-1; libpython2.7 2.7.16-2+deb10u4; libpython2.7-minimal 2.7.16-2+deb10u4; libpython2.7-stdlib 2.7.16-2+deb10u4; libpython3-stdlib 3.7.3-1; libpython3.5-minimal 3.5.3-1+deb9u5; libpython3.7-minimal 3.7.3-2+deb10u7 (+28 more) accepted_risk open
Library dh-python 2.20170125; libpython-stdlib 2.7.13-2; libpython2.7 2.7.13-2+deb9u6; libpython2.7-minimal 2.7.13-2+deb9u6; libpython2.7-stdlib 2.7.13-2+deb9u6; libpython3-stdlib 3.5.3-1; libpython3.5 3.5.3-1+deb9u5; libpython3.5-minimal 3.5.3-1+deb9u5 (+21 more) accepted_risk open
Saiph libpython-stdlib 2.7.16-1; libpython2-stdlib 2.7.16-1; libpython2.7 2.7.16-2+deb10u4; libpython2.7-minimal 2.7.16-2+deb10u4; libpython2.7-stdlib 2.7.16-2+deb10u4; libpython3-stdlib 3.7.3-1; libpython3.5-minimal 3.5.3-1+deb9u1; libpython3.7 3.7.3-2+deb10u7 (+23 more) accepted_risk open
morris alt-python-internal 3.11.13; alt-python-internal-libs 3.11.13; alt-python-internal-pip-wheel 21.3.1; alt-python-internal-setuptools-wheel 65.6.3; alt-python-virtualenv 20.13.0; alt-python27 2.7.18; alt-python27-alembic 0.8.3; alt-python27-argparse 1.2.1 (+341 more) does_not_affect open
mufasa abrt-addon-python 2.1.11; abrt-python 2.1.11; alt-python-internal 3.11.13; alt-python-internal-libs 3.11.13; alt-python-internal-pip-wheel 21.3.1; alt-python-internal-setuptools-wheel 65.6.3; alt-python-virtualenv 20.13.0; alt-python27 2.7.18 (+198 more) does_not_affect open
Bullseye libpython3-stdlib 3.9.2-3; libpython3.9 3.9.2-1+deb11u7; libpython3.9-minimal 3.9.2-1+deb11u7; libpython3.9-stdlib 3.9.2-1+deb11u7; python-apt-common 2.2.1.1; python3 3.9.2-3; python3-apt 2.2.1.1; python3-certifi 2020.6.20-1 (+30 more) none
Helios libpython3-stdlib 3.9.2-3; libpython3.9 3.9.2-1+deb11u7; libpython3.9-minimal 3.9.2-1+deb11u7; libpython3.9-stdlib 3.9.2-1+deb11u7; python-apt-common 2.2.1.1; python-is-python3 3.9.2-1; python3 3.9.2-3; python3-apt 2.2.1.1 (+29 more) none
Janus libpython2.7 2.7.16-2+deb10u4; libpython2.7-minimal 2.7.16-2+deb10u4; libpython2.7-stdlib 2.7.16-2+deb10u4; libpython3-stdlib 3.7.3-1; libpython3.7-minimal 3.7.3-2+deb10u7; libpython3.7-stdlib 3.7.3-2+deb10u7; python3 3.7.3-1; python3-minimal 3.7.3-1 (+2 more) none
Matrix libpython2.7-minimal 2.7.18-8+deb11u1; libpython2.7-stdlib 2.7.18-8+deb11u1; libpython3-stdlib 3.11.2-1+b1; libpython3.11 3.11.2-6+deb12u8; libpython3.11-minimal 3.11.2-6+deb12u8; libpython3.11-stdlib 3.11.2-6+deb12u8; python 2.7.16-1; python-apt-common 2.6.0 (+34 more) none
Silk alt-python-internal 3.11.14-1; alt-python-internal-libs 3.11.14-1; alt-python-internal-pip-wheel 21.3.1-1; alt-python-internal-setuptools-wheel 65.6.3-1; alt-python311 3.11.9-1; alt-python311-libs 3.11.9-1; alt-python311-pip-wheel 21.3.1-1; alt-python311-setuptools-wheel 65.6.3-1 (+50 more) none

Same product CVEs in your queue

Other tickets that look like the same product (from match reason). Relate them here to triage this CVE as the primary.

CVECVSSKEVSystemsStatus MatchedAlready related
CVE-2026-68770 9.8 morris, mufasa does_not_affect python
CVE-2026-3644 7.5 Archive, Library, Matrix, Saiph, morris accepted_risk, does_not_affect python
CVE-2026-7210 7.5 Archive, Library, Matrix, Saiph, morris accepted_risk, not_applicable python → CVE-2026-15308
CVE-2026-15308 7.5 Archive, Library, Matrix, Saiph, morris accepted_risk python
CVE-2026-59939 7.5 Bullseye, Matrix, Silk new python
CVE-2026-30922 7.5 Library not_applicable python → CVE-2026-59884
CVE-2026-59886 7.5 Library not_applicable python → CVE-2026-59884
CVE-2026-7246 7.2 Silk does_not_affect python

Related CVE (same fix)

Point this ticket’s CVE at a higher-priority / same-fix primary so you only triage one.

Host OS / kernel

OS
Debian GNU/Linux 9 (stretch) (9) · debian
Arch
x86_64
kernel_release
uname -r → 4.9.0-19-amd64
kernel_version
uname -v → #1 SMP Debian 4.9.320-2 (2022-06-30)

For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.

Same CVE on other hosts

Open the ticket for this CVE on another system.

System Status Priority Updated
morris does_not_affect 7.0 2026-08-22T10:15:58Z Open
mufasa does_not_affect 7.0 2026-08-22T10:15:58Z Open
Archive accepted_risk 0.62 2026-08-22T10:15:58Z Open
Saiph accepted_risk 0.62 2026-08-22T10:15:58Z Open

Description

When an Expat parser with a registered ElementDeclHandler parses an inline
document type definition containing a deeply nested content model a C stack
overflow occurs.

Determination

Vulnerable
Impact: Denial of service (process crash via stack overflow)
Attack: vectorNetwork (if the application parses attacker-controlled XML)
Requirements: Application must use xml.parsers.expat and register an ElementDeclHandler, then feed it a malicious DTD
Common in the wild?  Low — most applications do not register ElementDeclHandler
No public exposure or apps expose DoS

Update status

Also apply to other systems with this CVE:

Add note only

Also add note on:

Mitigation log

2026-08-05T14:45:38Z — affects
Vulnerable Impact: Denial of service (process crash via stack overflow) Attack: vectorNetwork (if the application parses attacker-controlled XML) Requirements: Application must use xml.parsers.expat and register an ElementDeclHandler, then feed it a malicious DTD Common in the wild? Low — most applications do not register ElementDeclHandler
2026-08-05T14:46:21Z — accepted_risk
No public exposure or apps expose DoS

References

NVD: CVE-2026-4224