Impact
The roxmltree library, up to version 0.21.1, performs a quadratic‑time validation of XML attributes and namespaces without imposing any limit on the number of attributes. Because the algorithm simply compares each attribute against every other, an attacker can construct an XML document that contains tens of thousands of attributes on a single element. Parsing such a document exhausts CPU time, potentially starving the host system and causing a service interruption. This vulnerability is classified as CWE‑407, Excessive Computation.
Affected Systems
The flaw affects the RazrFalcon roxmltree crate through all releases up to 0.21.1. The crate is commonly used in Rust applications that process XML data, particularly those that accept XML from untrusted sources such as web services, API endpoints, or file uploads.
Risk and Exploitability
The CVSS score of 8.7 signals a high severity. EPSS data is not available, and the issue is not listed in the CISA KEV catalog, so the overall exploitation probability depends largely on exposure. The likely attack vector is remote, where a program that employs roxmltree receives an XML payload from a network location; alternatively, if the application runs with elevated privileges locally, a malicious user could trigger the DoS by feeding a crafted XML file. Successful exploitation will result in resource exhaustion and denial of service but does not provide direct access to the system’s data or control.
OpenCVE Enrichment