Bug 2536068 (CVE-2026-92987)

Summary: CVE-2026-92987 roxmltree: roxmltree: Denial of Service via Quadratic Parsing
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: dbosanac, eborisov, jcantril, jreimann, lball, mdessi, mrizzi, ngough, pcattana, rekumar, rhel-process-autobot, rojacob, veshanka, vvoronko, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in roxmltree. This vulnerability allows a remote attacker to cause a denial of service (DoS) by crafting a malicious XML document with a large number of attributes on a single element. The roxmltree library performs quadratic-time validation of attributes and namespaces during XML parsing without imposing limits on the attribute count, leading to excessive CPU consumption.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2537034, 2537035, 2537036, 2537037, 2537038, 2537039, 2537040, 2537041, 2537042, 2537044, 2537045, 2537047, 2537048, 2537049, 2537050, 2537051, 2537052, 2537053, 2537054, 2537055, 2537056, 2537057, 2537058, 2537059, 2537043, 2537046    
Bug Blocks:    

Description OSIDB Bzimport 2026-09-17 14:40:12 UTC
roxmltree through 0.21.1 performs quadratic-time attribute and namespace validation during XML parsing without limits on attribute count. Attackers can craft XML documents with tens of thousands of attributes on a single element to consume excessive CPU time and cause denial of service.