AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2018-14647

HIGH · CVSS 7.5 EPSS 11.30%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-09-25 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2018-14647
Severity
HIGH
CVSS
7.5
EPSS
11.30%

Original Filing — NVD Description

Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions in Expat's internal data structures, consuming large amounts CPU and RAM. The vulnerability exists in Python versions 3.7.0, 3.6.0 through 3.6.6, 3.5.0 through 3.5.6, 3.4.0 through 3.4.9, 2.7.0 through 2.7.15.