CVE-2026-4645 PUBLISHED

Github.com/antchfx/xpath: xpath: denial of service via crafted boolean xpath expressions

Assigner: redhat
Reserved: 23.03.2026 Published: 23.03.2026 Updated: 23.03.2026

A flaw was found in the github.com/antchfx/xpath component. A remote attacker could exploit this vulnerability by submitting crafted Boolean XPath expressions that evaluate to true. This can cause an infinite loop in the logicalQuery.Select function, leading to 100% CPU utilization and a Denial of Service (DoS) condition for the affected system.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 7.5

Product Status

Vendor Red Hat
Product Compliance Operator
Versions Default: affected
Vendor Red Hat
Product Compliance Operator
Versions Default: affected
Vendor Red Hat
Product File Integrity Operator
Versions Default: affected
Vendor Red Hat
Product File Integrity Operator
Versions Default: affected
Vendor Red Hat
Product File Integrity Operator
Versions Default: affected
Vendor Red Hat
Product File Integrity Operator
Versions Default: affected
Vendor Red Hat
Product Migration Toolkit for Applications 8
Versions Default: affected
Vendor Red Hat
Product Migration Toolkit for Applications 8
Versions Default: affected
Vendor Red Hat
Product Migration Toolkit for Applications 8
Versions Default: affected
Vendor Red Hat
Product Migration Toolkit for Applications 8
Versions Default: affected
Vendor Red Hat
Product Migration Toolkit for Applications 8
Versions Default: affected
Vendor Red Hat
Product Migration Toolkit for Applications 8
Versions Default: affected
Vendor Red Hat
Product Red Hat Advanced Cluster Management for Kubernetes 2
Versions Default: affected
Vendor Red Hat
Product Red Hat Enterprise Linux 10
Versions Default: affected
Vendor Red Hat
Product Red Hat Enterprise Linux 9
Versions Default: affected
Vendor Red Hat
Product Red Hat OpenShift Container Platform 4
Versions Default: affected
Vendor Red Hat
Product Red Hat OpenShift Container Platform 4
Versions Default: affected
Vendor Red Hat
Product Red Hat OpenShift Container Platform 4
Versions Default: affected
Vendor Red Hat
Product Red Hat OpenShift distributed tracing 3
Versions Default: affected
Vendor Red Hat
Product Red Hat OpenShift distributed tracing 3
Versions Default: affected
Vendor Red Hat
Product Red Hat OpenShift distributed tracing 3
Versions Default: affected
Vendor Red Hat
Product Red Hat OpenShift distributed tracing 3
Versions Default: affected

References

Problem Types

  • Loop with Unreachable Exit Condition ('Infinite Loop') CWE