CVE-2026-7210 @ mufasa
Package interrogation (copy)
Run on the host — click to copy a command. RPM
| Package | Commands |
|---|---|
| python-2.7.5-94.0.5.el7_9.tuxcare.els1 | |
| python-augeas-0.5.0-2.el7 | |
| python-babel-0.9.6-8.el7 | |
| python-backports-1.0-8.el7 | |
| python-backports-ssl_match_hostname-3.5.0.1-1.el7 | |
| python-chardet-2.2.1-3.el7 |
Inventory lookup
Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.
Suggestions: python · python-augeas · python-babel · python-backports · python-backports-ssl_match_hostname · python-chardet
| System | Matches | Ticket for CVE-2026-7210 | |
|---|---|---|---|
| morris | python-backports 1.0; python-backports-ssl_match_hostname 3.5.0.1 | not_applicable open | |
| mufasa | python-backports 1.0; python-backports-ssl_match_hostname 3.5.0.1 | not_applicable open |
Same product CVEs in your queue
Other tickets that look like the same product (from match reason). Relate them here to triage this CVE as the primary.
| CVE | CVSS | KEV | Systems | Status | Matched | Already related | |
|---|---|---|---|---|---|---|---|
| CVE-2026-68770 | 9.8 | morris, mufasa | does_not_affect | python | — | ||
| CVE-2026-3644 | 7.5 | Archive, Library, Matrix, Saiph, morris … | accepted_risk, does_not_affect | python-chardet | — | ||
| CVE-2026-4224 | 7.5 | Archive, Library, Saiph, morris, mufasa | accepted_risk, does_not_affect | python-chardet | — | ||
| CVE-2026-15308 | 7.5 | Archive, Library, Matrix, Saiph, morris … | accepted_risk | python-chardet | — | ||
| CVE-2026-59939 | 7.5 | Bullseye, Matrix, Silk | new | python | — | ||
| CVE-2026-30922 | 7.5 | Library | not_applicable | python | → CVE-2026-59884 | ||
| CVE-2026-59886 | 7.5 | Library | not_applicable | python | → CVE-2026-59884 | ||
| CVE-2026-7246 | 7.2 | Silk | does_not_affect | python | — |
Related CVE (same fix)
This CVE is subordinated to primary CVE-2026-15308 — same product as CVE-2026-15308
Host OS / kernel
uname -r → 3.10.0-962.3.2.lve1.5.89.el7.x86_64uname -v → #1 SMP Thu Jul 9 15:55:31 UTC 2026For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.
Same CVE on other hosts
Open the ticket for this CVE on another system.
| System | Status | Priority | Updated | |
|---|---|---|---|---|
| morris | not_applicable | 7.0 | 2026-08-22T10:15:56Z | Open |
| Library | accepted_risk | 1.75 | 2026-08-22T10:15:55Z | Open |
| Matrix | accepted_risk | 1.75 | 2026-08-22T10:15:55Z | Open |
| Archive | accepted_risk | 0.62 | 2026-08-22T10:15:55Z | Open |
| Saiph | accepted_risk | 0.62 | 2026-08-22T10:15:55Z | Open |
Description
`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.
Determination
Related to primary CVE-2026-15308: same product as CVE-2026-15308
Update status
Add note only
Mitigation log
References
- https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4
- https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566
- https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56
- https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b
- https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286
- https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a
- https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f
- https://github.com/python/cpython/issues/149018
- https://github.com/python/cpython/pull/149023
- https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/
- http://www.openwall.com/lists/oss-security/2026/05/11/13
- http://www.openwall.com/lists/oss-security/2026/05/11/8
NVD: CVE-2026-7210