Description
roxmltree through 0.21.1 performs quadratic-time attribute and namespace validation during XML parsing without limits on attribute count. Attackers can craft XML documents with tens of thousands of attributes on a single element to consume excessive CPU time and cause denial of service.
Published: 2026-09-17
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via excessive CPU consumption
Action: Update Library
AI Analysis

Impact

The roxmltree library, up to version 0.21.1, performs a quadratic‑time validation of XML attributes and namespaces without imposing any limit on the number of attributes. Because the algorithm simply compares each attribute against every other, an attacker can construct an XML document that contains tens of thousands of attributes on a single element. Parsing such a document exhausts CPU time, potentially starving the host system and causing a service interruption. This vulnerability is classified as CWE‑407, Excessive Computation.

Affected Systems

The flaw affects the RazrFalcon roxmltree crate through all releases up to 0.21.1. The crate is commonly used in Rust applications that process XML data, particularly those that accept XML from untrusted sources such as web services, API endpoints, or file uploads.

Risk and Exploitability

The CVSS score of 8.7 signals a high severity. EPSS data is not available, and the issue is not listed in the CISA KEV catalog, so the overall exploitation probability depends largely on exposure. The likely attack vector is remote, where a program that employs roxmltree receives an XML payload from a network location; alternatively, if the application runs with elevated privileges locally, a malicious user could trigger the DoS by feeding a crafted XML file. Successful exploitation will result in resource exhaustion and denial of service but does not provide direct access to the system’s data or control.

Generated by OpenCVE AI on September 17, 2026 at 20:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to roxmltree 0.22.0 or later, where the quadratic validation has been removed or bounded.
  • If an upgrade is not currently possible, add application‑level checks that limit the number of attributes per element before handing the XML to the library, following the CWE‑407 best practice of bounding resource consumption.
  • Run the XML parsing routine inside a container or sandbox that enforces CPU and memory quotas to contain any accidental or malicious overconsumption.

Generated by OpenCVE AI on September 17, 2026 at 20:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1050
References
Metrics threat_severity

None

threat_severity

Important


Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Razrfalcon
Razrfalcon roxmltree
Vendors & Products Razrfalcon
Razrfalcon roxmltree

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description roxmltree through 0.21.1 performs quadratic-time attribute and namespace validation during XML parsing without limits on attribute count. Attackers can craft XML documents with tens of thousands of attributes on a single element to consume excessive CPU time and cause denial of service.
Title roxmltree through 0.21.1 Denial of Service via Quadratic Parsing
Weaknesses CWE-407
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Razrfalcon Roxmltree
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:59.550Z

Reserved: 2026-09-17T13:55:54.643Z

Link: CVE-2026-92987

cve-icon Vulnrichment

Updated: 2026-09-17T15:32:09.721Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T15:17:02.203

Modified: 2026-09-22T20:43:58.793

Link: CVE-2026-92987

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-17T14:22:10Z

Links: CVE-2026-92987 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:00:17Z

Weaknesses
  • CWE-1050

    Excessive Platform Resource Consumption within a Loop

  • CWE-407

    Inefficient Algorithmic Complexity