CVE-2026-7210
HighAdvisory
Published 11 May 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.007
- 50th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 733
- of 17,787 indexed, latest versions
- Container images
- 721
- deployed by those charts
- Fix available
- 6 of 17
- affected packages
The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection
Carried by container images the latest versions of 733 of 17,787 indexed charts deploy, on 721 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| python3.11deb | 3.11.0~rc1-1~22.04, 3.11.0~rc1-1~22.04.1, 3.11.2-6, 3.11.2-6+deb12u2+6 more | no fix listed | 180 |
| python3.8deb | 3.8.5-1~20.04, 3.8.5-1~20.04.2, 3.8.5-1~20.04.3, 3.8.10-0ubuntu1~20.04+11 more | no fix listed | 100 |
| python3.12deb | 3.12.3-1, 3.12.3-1ubuntu0.2, 3.12.3-1ubuntu0.3, 3.12.3-1ubuntu0.4+11 more | no fix listed | 87 |
| python3.10deb | 3.10.4-3, 3.10.4-3ubuntu0.1, 3.10.6-1~22.04, 3.10.6-1~22.04.1+16 more | no fix listed | 80 |
| python3apk | 3.11.12-r1, 3.12.8-r1, 3.12.9-r0, 3.12.10-r0+7 more | 3.12.14-r0, 3.14.7-r0 | 75 |
| python3.13deb | 3.13.5-2, 3.13.5-2+deb13u2, 3.13.5-2+deb13u4, 3.13.7-1ubuntu0.1 | no fix listed | 74 |
| python2.7deb | 2.7.6-8, 2.7.6-8ubuntu0.4, 2.7.12-1ubuntu0~16.04.2, 2.7.12-1ubuntu0~16.04.3+12 more | 2.7.12-1ubuntu0~16.04.18+esm20 | 54 |
| python3.6deb | 3.6.6-1~18.04, 3.6.7-1~18.04, 3.6.9-1~18.04, 3.6.9-1~18.04ubuntu1+7 more | no fix listed | 44 |
| python3.5deb | 3.5.2-2ubuntu0~16.04.1, 3.5.2-2ubuntu0~16.04.4, 3.5.2-2ubuntu0~16.04.5, 3.5.2-2ubuntu0~16.04.9 | 3.5.2-2ubuntu0~16.04.13+esm23 | 25 |
| python3.14deb | 3.14.4-1, 3.14.4-1ubuntu0.1, 3.14.4-1ubuntu0.2 | no fix listed | 9 |
| python3.4deb | 3.4.0-2ubuntu1, 3.4.3-1ubuntu1~14.04.5, 3.4.3-1ubuntu1~14.04.6, 3.4.3-1ubuntu1~14.04.7 | no fix listed | 7 |
| pythonbitnami | 3.11.11-0, 3.12.8-0, 3.13.5-1 | 3.13.14 | 3 |
| python-3.12apk | 3.12.0-r1, 3.12.9-r1, 3.12.14-r2, 3.12.14-r6 | no fix listed | 8 |
| python-3.14apk | 3.14.2-r2, 3.14.4-r2, 3.14.6-r0 | 3.14.6-r1 | 6 |
| python-3.13apk | 3.13.7-r0, 3.13.10-r0, 3.13.12-r2 | 3.13.14-r0 | 3 |
| python-3.11apk | 3.11.16-r5 | no fix listed | 1 |
| python3rpm | 3.12.9-13.azl3 | no fix listed | 1 |
- OSV records
- ALPINE-CVE-2026-7210BIT-python-2026-7210DEBIAN-CVE-2026-7210UBUNTU-CVE-2026-7210CGA-4h64-mv2w-5hppCGA-4jp4-99xm-3q68CGA-4wm6-gw95-xqv3CGA-fgg5-525j-xp8pAZL-86784
- Also known as
- BIT-libpython-2026-7210, BIT-python-min-2026-7210, CGA-6g24-ph8m-vj9m, CGA-f2xq-5g85-fcv8, CGA-mp75-hrgp-9999, CGA-rgc2-288h-x4jp, PSF-2026-23, USN-8524-1
Charts affected
733 by stars
Container images carrying it
721 by charts deploying them
A fixed version is listed for 6 of the 17 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ymuski/ | 5ba7fd8c7bdc | python3 | 3.12.14-r0 | 1 |
| zabbix/ | 0e5f69c4c54e | python3.12 | no fix listed | 1 |
| zabbix/ | 01de79c31391 | python3.8 | no fix listed | 1 |
| zabbix/ | 7d4d58086515 | python3.12 | no fix listed | 1 |
| zabbix/ | 99e9a090b516 | python3.10 | no fix listed | 1 |
| zooproject/ | 9a507cb7e2dd | python3.10 | no fix listed | 1 |
| gcr.io/ | 5ea7b7f3632a | python3.5 | 3.5.2-2ubuntu0~16.04.13+esm23 | 1 |
| gcr.io/ | 8f9ff98fdbef | python3.5 | 3.5.2-2ubuntu0~16.04.13+esm23 | 1 |
| gcr.io/ | 9bcfd2abc361 | python3.11 | no fix listed | 1 |
| ghcr.io/ | 459010a02aff | python3.12 | no fix listed | 1 |
| ghcr.io/ | 13e267ad7d94 | python3.12 | no fix listed | 1 |
| ghcr.io/ | f9104080d9a7 | python3.13 | no fix listed | 1 |
| ghcr.io/ | fcbab3a24880 | python3 | 3.12.14-r0 | 1 |
| ghcr.io/ | 5889bea38e56 | python3.11 | no fix listed | 1 |
| ghcr.io/ | 8766ba08bf1a | python3.11 | no fix listed | 1 |
| ghcr.io/ | 8eb6e492fe3c | python3.12 | no fix listed | 1 |
| ghcr.io/ | 1aba0ffe55ea | python3.10 | no fix listed | 1 |
| ghcr.io/ | ab63d26a8a2c | python-3.13 | 3.13.14-r0 | 1 |
| ghcr.io/ | 72f35584026d | python3.11 | no fix listed | 1 |
| ghcr.io/ | 6fde1edc0983 | python3.8 | no fix listed | 1 |
| ghcr.io/ | d600eac6283f | python3.12 | no fix listed | 1 |
| ghcr.io/ | 2ed0183564d7 | python3.12 | no fix listed | 1 |
| ghcr.io/ | 853e6f105b51 | python3.12 | no fix listed | 1 |
| ghcr.io/ | ca7dc7362968 | python3.11 | no fix listed | 1 |
| ghcr.io/ | 0e99f12bb040 | python3.11 | no fix listed | 1 |
| ghcr.io/ | 8d943799621b | python3.11 | no fix listed | 1 |
| ghcr.io/ | 726a947bb65b | python3.11 | no fix listed | 1 |
| ghcr.io/ | c7cd53ad559a | python3.12 | no fix listed | 1 |
| ghcr.io/ | fce5b6fd161c | python3 | 3.14.7-r0 | 1 |
| ghcr.io/ | 8c05f7366981 | python3.13 | no fix listed | 1 |
| ghcr.io/ | a2be95de450c | python3.13 | no fix listed | 1 |
| ghcr.io/ | 16fda01ae58a | python3.11 | no fix listed | 1 |
| ghcr.io/ | 7fe76551a78e | python3 | 3.12.14-r0 | 1 |
| ghcr.io/ | 3225d2bc6b3c | python3.13 | no fix listed | 1 |
| ghcr.io/ | 8ac53eb38393 | python | 3.13.14 | 1 |
| ghcr.io/ | ff0cd9db78d3 | python3 | 3.12.14-r0 | 1 |
| ghcr.io/ | e59ebde55709 | python3.13 | no fix listed | 1 |
| ghcr.io/ | 7a50c07e7c69 | python3.12 | no fix listed | 1 |
| ghcr.io/ | 6e82914e1051 | python3.11 | no fix listed | 1 |
| ghcr.io/ | bcd5b8d4c45c | python3.6 | no fix listed | 1 |
| ghcr.io/ | ebcf66281fc1 | python3.11 | no fix listed | 1 |
| ghcr.io/ | c99e8ef2c545 | python3 | 3.12.14-r0 | 1 |
| ghcr.io/ | 6efef5d19d56 | python3 | 3.12.14-r0 | 1 |
| ghcr.io/ | 10f8d164109b | python3.13 | no fix listed | 1 |
| ghcr.io/ | 472a25038957 | python3.11 | no fix listed | 1 |
| ghcr.io/ | 06a16d4f279f | python3.12 | no fix listed | 1 |
| ghcr.io/ | 3fbe4c29d14c | python2.7 python3.8 | no fix listed no fix listed | 1 |
| ghcr.io/ | 07198d49e5b4 | python3 | 3.12.14-r0 | 1 |
| ghcr.io/ | cd25a5cc3f1b | python3.13 | no fix listed | 1 |
| ghcr.io/ | 6d4106724d56 | python3.11 | no fix listed | 1 |