OurCVEs
Register
Back to feed
High
DEBIAN-CVE-2026-91765

Published Sep 25, 2026

CVSS

7.5

HIGH

EPSS

Exploit Prediction Scoring System — the modeled probability of in-the-wild exploitation in the next 30 days.
—

Affected packages

0
Summary

cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing tens of thousands of nested elements to any SoapServer endpoint, exhaust the stack and crash the process. The same unbounded recursion exists in the SOAP value decoder and in the WSDL node search helper.

Developer impact

Recommended action

Affected packages
Sources