PT-2026-28438 · Unknown · Logicalquery.Select

Published

2026-03-17

·

Updated

2026-05-20

·

CVE-2026-32287

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions versions prior to 2026-32287
Description Boolean XPath expressions that evaluate to true can cause an infinite loop within the logicalQuery.Select function, resulting in 100% CPU utilization. This condition can be initiated by top-level selectors like "1=1" or "true()".
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Resource Exhaustion

Infinite Loop

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-AP92343
CLEANSTART-2026-BU65096
CLEANSTART-2026-DQ17669
CLEANSTART-2026-FH54780
CLEANSTART-2026-FV86809
CLEANSTART-2026-KC83705
CLEANSTART-2026-ML41879
CLEANSTART-2026-QV77143
CLEANSTART-2026-VT65447
CLEANSTART-2026-WA84208
CVE-2026-32287
GHSA-65XW-VW82-R86X
GO-2026-4526
SUSE-SU-2026:1135-1

Affected Products

Logicalquery.Select