CVE Tracker

CVE-2026-7210 @ Saiph

Status
accepted_risk
Priority
0.62
Match score
4.0
Risk
DoS Remote
CVSS
7.5 HIGH
Reason
cpe: python; pkgs: python, python-crypto, python-dnspython, python-gpg, python-ldb, python-minimal; version: in-range: python-stdlib-2.7.16-1, python-2.7.16-1, python-crypto-2.6.1-9+b1, python-dnspython-1.16.0-1+deb10u1, python-gpg-1.12.0-6, python-ldb-1.5.1+really1.4.6-3+deb10u1; risk:dos
Created
2026-08-03T17:04:25Z
Updated
2026-08-22T10:15:55Z
Closed
2026-08-03T18:07:44Z

Package interrogation (copy)

Run on the host — click to copy a command. Debian/apt

PackageCommands
python-stdlib-2.7.16-1
python-2.7.16-1
python-crypto-2.6.1-9+b1
python-dnspython-1.16.0-1+deb10u1
python-gpg-1.12.0-6
python-ldb-1.5.1+really1.4.6-3+deb10u1
python-minimal

Inventory lookup

Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.

Clear

Suggestions: python-stdlib · python · python-crypto · python-dnspython · python-gpg · python-ldb · python-minimal

SystemMatchesTicket for CVE-2026-7210
Archive libpython-stdlib 2.7.16-1 accepted_risk open
Library libpython-stdlib 2.7.13-2 accepted_risk open
Saiph libpython-stdlib 2.7.16-1 accepted_risk open

Same product CVEs in your queue

Other tickets that look like the same product (from match reason). Relate them here to triage this CVE as the primary.

CVECVSSKEVSystemsStatus MatchedAlready related
CVE-2026-68770 9.8 morris, mufasa does_not_affect python
CVE-2026-3644 7.5 Archive, Library, Matrix, Saiph, morris accepted_risk, does_not_affect python
CVE-2026-4224 7.5 Archive, Library, Saiph, morris, mufasa accepted_risk, does_not_affect python
CVE-2026-15308 7.5 Archive, Library, Matrix, Saiph, morris accepted_risk python
CVE-2026-59939 7.5 Bullseye, Matrix, Silk new python
CVE-2026-30922 7.5 Library not_applicable python → CVE-2026-59884
CVE-2026-59886 7.5 Library not_applicable python → CVE-2026-59884
CVE-2026-7246 7.2 Silk does_not_affect python

Related CVE (same fix)

This CVE is subordinated to primary CVE-2026-15308 — same product as CVE-2026-15308

Host OS / kernel

OS
Debian GNU/Linux 10 (buster) (10) · debian
Arch
x86_64
kernel_release
uname -r → 4.19.0-27-amd64
kernel_version
uname -v → #1 SMP Debian 4.19.316-1 (2024-06-25)

For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.

Same CVE on other hosts

Open the ticket for this CVE on another system.

System Status Priority Updated
morris not_applicable 7.0 2026-08-22T10:15:56Z Open
mufasa not_applicable 7.0 2026-08-22T10:15:56Z Open
Library accepted_risk 1.75 2026-08-22T10:15:55Z Open
Matrix accepted_risk 1.75 2026-08-22T10:15:55Z Open
Archive accepted_risk 0.62 2026-08-22T10:15:55Z Open

Description

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

Determination

Cascaded from primary CVE-2026-15308: These servers have no public use that would cause this issue. Only high CPU is risk.

Update status

Also apply to other systems with this CVE:

Add note only

Also add note on:

Mitigation log

2026-08-03T18:07:44Z — accepted_risk
Cascaded from primary CVE-2026-15308: These servers have no public use that would cause this issue. Only high CPU is risk.

References

NVD: CVE-2026-7210