AZL-105209

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105209.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-105209
Upstream
Published
2026-09-17T15:17:02Z
Modified
2026-10-03T05:35:10Z
Summary
CVE-2026-92987 affecting package openvmm 0.1.0-1
Details

roxmltree through 0.21.1 performs quadratic-time attribute and namespace validation during XML parsing without limits on attribute count. Attackers can craft XML documents with tens of thousands of attributes on a single element to consume excessive CPU time and cause denial of service.

References

Affected packages

Azure Linux:3 / openvmm

Package

Name
openvmm
Purl
pkg:rpm/azure-linux/openvmm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
0.1.0-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105209.json"