{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aroxmltreeroxmltree/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:roxmltree:roxmltree:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-92987"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["roxmltree (\u003c= 0.21.1)"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["roxmltree"],"content_html":"\u003cp\u003eThe roxmltree library (versions 0.21.1 and earlier) is susceptible to a denial of service vulnerability triggered by inefficient attribute and namespace validation during XML parsing. The implementation lacks sufficient limits on the number of attributes processed for a single XML element, resulting in quadratic-time complexity. An unauthenticated attacker can exploit this by submitting a specially crafted XML payload containing an extremely large number of attributes on a single node. When the application parses this malicious document, the CPU utilization spikes to maximum capacity, rendering the service unresponsive. This vulnerability poses a significant risk to any application that uses roxmltree to process user-supplied XML data without external validation or input size constraints.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in service unavailability via resource exhaustion, specifically targeting the CPU. This impacts any environment utilizing affected versions of the roxmltree library for XML parsing, particularly internet-facing services that accept arbitrary XML input.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the roxmltree library to a version containing the fix for CVE-2026-92987.\u003c/li\u003e\n\u003cli\u003eImplement input validation on the application layer to restrict the maximum number of attributes allowed per XML element before passing the data to the parser.\u003c/li\u003e\n\u003cli\u003eMonitor application logs and system performance metrics for sudden spikes in CPU utilization originating from service processes responsible for handling XML input.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-17T16:02:03Z","date_published":"2026-09-17T16:02:03Z","id":"https://feed.craftedsignal.io/briefs/2026-09-roxmltree-dos/","summary":"The roxmltree library is vulnerable to a denial of service attack due to quadratic-time attribute and namespace validation during XML parsing, allowing attackers to cause excessive CPU consumption.","title":"Denial of Service Vulnerability in roxmltree","url":"https://feed.craftedsignal.io/briefs/2026-09-roxmltree-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:roxmltree:roxmltree:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}