CVE-2026-7210 @ Saiph
Package interrogation (copy)
Run on the host — click to copy a command. Debian/apt
| Package | Commands |
|---|---|
| python-stdlib-2.7.16-1 | |
| python-2.7.16-1 | |
| python-crypto-2.6.1-9+b1 | |
| python-dnspython-1.16.0-1+deb10u1 | |
| python-gpg-1.12.0-6 | |
| python-ldb-1.5.1+really1.4.6-3+deb10u1 | |
| python-minimal |
Inventory lookup
Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.
Suggestions: python-stdlib · python · python-crypto · python-dnspython · python-gpg · python-ldb · python-minimal
| System | Matches | Ticket for CVE-2026-7210 | |
|---|---|---|---|
| Archive | libpython-stdlib 2.7.16-1 | accepted_risk open | |
| Library | libpython-stdlib 2.7.13-2 | accepted_risk open | |
| Saiph | libpython-stdlib 2.7.16-1 | accepted_risk open |
Same product CVEs in your queue
Other tickets that look like the same product (from match reason). Relate them here to triage this CVE as the primary.
| CVE | CVSS | KEV | Systems | Status | Matched | Already related | |
|---|---|---|---|---|---|---|---|
| CVE-2026-68770 | 9.8 | morris, mufasa | does_not_affect | python | — | ||
| CVE-2026-3644 | 7.5 | Archive, Library, Matrix, Saiph, morris … | accepted_risk, does_not_affect | python | — | ||
| CVE-2026-4224 | 7.5 | Archive, Library, Saiph, morris, mufasa | accepted_risk, does_not_affect | python | — | ||
| CVE-2026-15308 | 7.5 | Archive, Library, Matrix, Saiph, morris … | accepted_risk | python | — | ||
| CVE-2026-59939 | 7.5 | Bullseye, Matrix, Silk | new | python | — | ||
| CVE-2026-30922 | 7.5 | Library | not_applicable | python | → CVE-2026-59884 | ||
| CVE-2026-59886 | 7.5 | Library | not_applicable | python | → CVE-2026-59884 | ||
| CVE-2026-7246 | 7.2 | Silk | does_not_affect | python | — |
Related CVE (same fix)
This CVE is subordinated to primary CVE-2026-15308 — same product as CVE-2026-15308
Host OS / kernel
uname -r → 4.19.0-27-amd64uname -v → #1 SMP Debian 4.19.316-1 (2024-06-25)For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.
Same CVE on other hosts
Open the ticket for this CVE on another system.
| System | Status | Priority | Updated | |
|---|---|---|---|---|
| morris | not_applicable | 7.0 | 2026-08-22T10:15:56Z | Open |
| mufasa | not_applicable | 7.0 | 2026-08-22T10:15:56Z | Open |
| Library | accepted_risk | 1.75 | 2026-08-22T10:15:55Z | Open |
| Matrix | accepted_risk | 1.75 | 2026-08-22T10:15:55Z | Open |
| Archive | accepted_risk | 0.62 | 2026-08-22T10:15:55Z | Open |
Description
`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.
Determination
Cascaded from primary CVE-2026-15308: These servers have no public use that would cause this issue. Only high CPU is risk.
Update status
Add note only
Mitigation log
References
- https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4
- https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566
- https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56
- https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b
- https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286
- https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a
- https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f
- https://github.com/python/cpython/issues/149018
- https://github.com/python/cpython/pull/149023
- https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/
- http://www.openwall.com/lists/oss-security/2026/05/11/13
- http://www.openwall.com/lists/oss-security/2026/05/11/8
NVD: CVE-2026-7210