When an Expat parser with a registered ElementDeclHandler parses an inline
document type definition containing a deeply nested content model a C stack
overflow occurs.
Metrics
Affected Vendors & Products
References
History
Tue, 17 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Python
Python cpython |
|
| Vendors & Products |
Python
Python cpython |
Tue, 17 Mar 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 17 Mar 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-805 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Mon, 16 Mar 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-674 | |
| Metrics |
ssvc
|
Mon, 16 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs. | |
| Title | Stack overflow parsing XML with deeply nested DTD content models | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: PSF
Published: 2026-03-16T17:52:26.639Z
Updated: 2026-03-16T23:08:21.692Z
Reserved: 2026-03-15T18:10:54.886Z
Link: CVE-2026-4224
Updated: 2026-03-16T23:08:21.692Z
Status : Awaiting Analysis
Published: 2026-03-16T18:16:10.070
Modified: 2026-03-17T14:20:01.670
Link: CVE-2026-4224
ReportizFlow