🔐 CVE Alert

CVE-2026-4224

UNKNOWN 0.0

Stack overflow parsing XML with deeply nested DTD content models

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
5th

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.

Vendor python software foundation
Product cpython
Published Mar 16, 2026
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for python software foundation cpython

Be the first to know when new unknown vulnerabilities affecting python software foundation cpython are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Python Software Foundation / CPython
0 < 3.13.13 3.14.0 < 3.14.4 3.15.0a1 < 3.15.0a8

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/python/cpython/commit/eb0e8be3a7e11b87d198a2c3af1ed0eccf532768 mail.python.org: https://mail.python.org/archives/list/[email protected]/thread/5M7CGUW3XBRY7II4DK43KF7NQQ3TPZ6R/ github.com: https://github.com/python/cpython/issues/145986 github.com: https://github.com/python/cpython/pull/145987 github.com: https://github.com/python/cpython/commit/196edfb06a7458377d4d0f4b3cd41724c1f3bd4a github.com: https://github.com/python/cpython/commit/e0a8a6da90597a924b300debe045cdb4628ee1f3 github.com: https://github.com/python/cpython/commit/642865ddf4b232da1f3b1f7abcfa3254c4bfe785 github.com: https://github.com/python/cpython/commit/af856a7177326ac25d9f66cc6dd28b554d914fee openwall.com: http://www.openwall.com/lists/oss-security/2026/03/16/4

Credits

🔍 Gil Portnoy Stan Ulbrych Bénédikt Tran Stan Ulbrych