Report: CVE-2026-4645 - Github.com/antchfx/xpath: xpath: denial of service via crafted boolean xpath expr

Report: CVE-2026-4645 - Github.com/antchfx/xpath: xpath: denial of service via crafted boolean xpath expr

CVE ID :CVE-2026-4645 Published : March 23, 2026, 2:16 p.m. | 1 hour, 25 minutes ago Description :A flaw was found in the `github.com/antchfx/xpath` component. A remote attacker could exploit this vulnerability by submitting crafted Boolean XPath expressions that evaluate to true. This can cause an infinite loop in the `logicalQuery.Select` function, leading to 100% CPU utilization and a Denial of Service (DoS) condition for the affected system. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
March 23, 2026
Affected Product: github
Impact: Denial of Service