Denial of Service Vulnerability in roxmltree XML Parsing Tool
CVE-2026-92987
8.7HIGH
What is CVE-2026-92987?
The roxmltree XML parsing library, up to version 0.21.1, is susceptible to a denial of service attack due to its quadratic-time complexity in attribute and namespace validation. This vulnerability allows attackers to craft XML documents with an excessive number of attributes, leading to significant CPU consumption and potential service disruption. By exploiting this flaw, attackers can create documents with tens of thousands of attributes in a single element, effectively overwhelming the system and causing degraded performance or complete service unavailability.
Affected Version(s)
roxmltree 0 <= 0.21.1
