CVE-2026-4224
Microsoft · Published March 19, 2026
7.5
CVSS v3.1
HIGHPatch availableGet patch
Description
Stack overflow parsing XML with deeply nested DTD content models. Stack overflow parsing XML with deeply nested DTD content models
Affected Products
- azl3 python3 3.12.9-9 on Azure Linux 3.0
- cbl2 python3 3.9.19-19 on CBL Mariner 2.0
- azl3 python3 3.12.9-10 on Azure Linux 3.0
- azl3 python3 3.12.9-13 on Azure Linux 3.0
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H