Denial of Service Vulnerability in roxmltree XML Parsing Tool
CVE-2026-92987

8.7HIGH

Key Information:

Vendor

Razrfalcon

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-92987?

The roxmltree XML parsing library, up to version 0.21.1, is susceptible to a denial of service attack due to its quadratic-time complexity in attribute and namespace validation. This vulnerability allows attackers to craft XML documents with an excessive number of attributes, leading to significant CPU consumption and potential service disruption. By exploiting this flaw, attackers can create documents with tens of thousands of attributes in a single element, effectively overwhelming the system and causing degraded performance or complete service unavailability.

Affected Version(s)

roxmltree 0 <= 0.21.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

trickyfalcon
.