CVE-2026-92987
7.5 HIGHpublic exploit availablePublished 2026-09-17 · Updated 2026-09-22
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
roxmltree through 0.21.1 performs quadratic-time attribute and namespace validation during XML parsing without limits on attribute count. Attackers can craft XML documents with tens of thousands of attributes on a single element to consume excessive CPU time and cause denial of service.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-407
Public exploit & PoC references
All references
- https://github.com/RazrFalcon/roxmltree
- https://github.com/RazrFalcon/roxmltree/blob/v0.21.1/src/lib.rs#L751-L755
- https://github.com/RazrFalcon/roxmltree/blob/v0.21.1/src/parse.rs#L1014-L1020
- https://github.com/RazrFalcon/roxmltree/issues/153
- https://www.vulncheck.com/advisories/roxmltree-through-0.21.1-denial-of-service-via-quadratic-parsing
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-100700PoC
- MEDIUMCVE-2026-102277PoC
- MEDIUMCVE-2026-19668
- LOWCVE-2026-44639PoC
- HIGHCVE-2026-61814PoC
- HIGHCVE-2026-63446PoC
- HIGHCVE-2026-63447PoC
- MEDIUMCVE-2026-63448PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.