Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 17 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 17 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | roxmltree through 0.21.1 performs quadratic-time attribute and namespace validation during XML parsing without limits on attribute count. Attackers can craft XML documents with tens of thousands of attributes on a single element to consume excessive CPU time and cause denial of service. | |
| Title | roxmltree through 0.21.1 Denial of Service via Quadratic Parsing | |
| Weaknesses | CWE-407 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-17T15:32:13.906Z
Reserved: 2026-09-17T13:55:54.643Z
Link: CVE-2026-92987
Updated: 2026-09-17T15:32:09.721Z
Status : Received
Published: 2026-09-17T15:17:02.203
Modified: 2026-09-17T16:18:35.340
Link: CVE-2026-92987
No data.
OpenCVE Enrichment
No data.