CVE-2026-4645Disclosure

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A flaw was found in the `github.com/antchfx/xpath` component. A remote attacker could exploit this vulnerability by submitting crafted Boolean XPath expressions that evaluate to true. This can cause an infinite loop in the `logicalQuery.Select` function, leading to 100% CPU utilization and a Denial of Service (DoS) condition for the affected system.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-23: 4PoC Mentioned / Linked · 2026-03-23: 1Technical Details · 2026-03-23: 203-23
Signal classification3 categories
Disclosure
250.0%
General
125.0%
PoC
125.0%
Referenced assets6 URLs
Full discourse4 posts
  • EdgeDetectOps@EdgeDetectOps
    General

    Most XPath DoS looks like a traffic spike. This CVE-2026-4645 isn't.

    Post summary

    The post merely notes that CVE‑2026‑4645’s DoS behaviour differs from typical XPath DoS patterns, providing no additional technical or exploit information.

    100004
    15 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    PoC

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4645 - http://Github.com/antchfx/xpath: xpath: denial of service via crafted boolean xpath expressions Intel Report: https://ift.tt/GcreMWk

    Post summary

    The alert announces CVE‑2026‑4645 as a denial‑of‑service flaw involving crafted XPath boolean expressions, and references a GitHub repository that likely contains relevant code, but provides no evidence of exploitation or patches.

    0000034
    289 followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-4645 - Red Hat - Compliance Operator - https://www.redpacketsecurity.com/cve-alert-cve-2026-4645-red-hat-compliance-operator/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-4645 #red-hat #compliance-operator

    Post summary

    A CVE alert for Red Hat Compliance Operator (CVE-2026-4645) is posted, but no additional technical, exploitation, or patch information is provided in the tweet.

    0000063
    3.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4645 XPath Denial of Service Vulnerability in http://github.com/antchfx/xpath ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4645 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The post announces CVE-2026‑4645 as an XPath DoS flaw in the antchfx/xpath Go library, providing links to a vulnerability database entry and customizable alerts, but it lacks any exploit code, active exploitation reports, or patch information.

    0000034
    4.0K followersView on X

Explore more