CVE-2026-91765
7.5 HIGHpublic exploit availablePublished 2026-09-25 · Updated 2026-09-29
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing tens of thousands of nested elements to any SoapServer endpoint, exhaust the stack and crash the process. The same unbounded recursion exists in the SOAP value decoder and in the WSDL node search helper.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-674
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-100702PoC
- MEDIUMCVE-2026-102265PoC
- HIGHCVE-2026-102276PoC
- HIGHCVE-2026-102278PoC
- HIGHCVE-2026-102281PoC
- HIGHCVE-2026-102495
- HIGHCVE-2026-102496
- HIGHCVE-2026-102497
Related by shared AI tags and CWE weakness class. Browse the full archive.