Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Trickyfalcon

#32686of 57,356
8.7Total CVSS
Vulnerabilities · 1
PT-2026-94360
8.7
2026-09-17
Pypi · Roxmltree · CVE-2026-92987
**Name of the Vulnerable Software and Affected Versions** roxmltree versions 0.21.1 and earlier **Description** An issue exists during XML parsing where quadratic-time attribute and namespace validation is performed without limits on the attribute count. An attacker can exploit this by crafting XML documents containing tens of thousands of attributes on a single element, leading to excessive CPU consumption and a denial of service. **Recommendations** Update roxmltree to a version later than 0.21.1.