Skip to content

Commit 2fb6d1f

Browse files
committed
gh-127502: Update XML vulnerability table
Python 3.11-3.15 include expat 2.7.1 which is not vulnerable. expat 2.6.0 was released in February 2024.
1 parent b150b6a commit 2fb6d1f

1 file changed

Lines changed: 3 additions & 3 deletions

File tree

Doc/library/xml.rst

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -63,12 +63,12 @@ the various modules are vulnerable to them.
6363
========================= ================== ================== ================== ================== ==================
6464
kind sax etree minidom pulldom xmlrpc
6565
========================= ================== ================== ================== ================== ==================
66-
billion laughs **Vulnerable** (1) **Vulnerable** (1) **Vulnerable** (1) **Vulnerable** (1) **Vulnerable** (1)
67-
quadratic blowup **Vulnerable** (1) **Vulnerable** (1) **Vulnerable** (1) **Vulnerable** (1) **Vulnerable** (1)
66+
billion laughs Safe (1) Safe (1) Safe (1) Safe (1) Safe (1)
67+
quadratic blowup Safe (1) Safe (1) Safe (1) Safe (1) Safe (1)
6868
external entity expansion Safe (5) Safe (2) Safe (3) Safe (5) Safe (4)
6969
`DTD`_ retrieval Safe (5) Safe Safe Safe (5) Safe
7070
decompression bomb Safe Safe Safe Safe **Vulnerable**
71-
large tokens **Vulnerable** (6) **Vulnerable** (6) **Vulnerable** (6) **Vulnerable** (6) **Vulnerable** (6)
71+
large tokens Safe (6) Safe (6) Safe (6) Safe (6) Safe (6)
7272
========================= ================== ================== ================== ================== ==================
7373

7474
1. Expat 2.4.1 and newer is not vulnerable to the "billion laughs" and

0 commit comments

Comments
 (0)