-
-
Notifications
You must be signed in to change notification settings - Fork 30.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Please upgrade bundled Expat to 2.6.0 (e.g. for the fix to CVE-2023-52425) #115399
Labels
Comments
This was referenced Feb 13, 2024
Thanks for letting us know. We'll be addressing this. |
GH-115468 is a backport of this pull request to the 3.11 branch. |
Yhg1s
pushed a commit
that referenced
this issue
Feb 14, 2024
miss-islington
pushed a commit
to miss-islington/cpython
that referenced
this issue
Feb 14, 2024
(cherry picked from commit 4b2d178) Co-authored-by: Seth Michael Larson <seth@python.org>
ambv
pushed a commit
that referenced
this issue
Feb 14, 2024
sethmlarson
added a commit
to sethmlarson/cpython
that referenced
this issue
Feb 14, 2024
…honGH-115468) Manual backport due to code differences. (cherry picked from commit e071b0d) Co-authored-by: Seth Michael Larson <seth@python.org>
GH-115474 is a backport of this pull request to the 3.9 branch. |
sethmlarson
added a commit
to sethmlarson/cpython
that referenced
this issue
Feb 14, 2024
…honGH-115468) Manual backport due to code differences. (cherry picked from commit e071b0d) Co-authored-by: Seth Michael Larson <seth@python.org>
GH-115475 is a backport of this pull request to the 3.8 branch. |
ambv
pushed a commit
that referenced
this issue
Feb 21, 2024
…5400) Doc/library/xml.rst: Document CVE-2023-52425 under "XML vulnerabilities"
miss-islington
pushed a commit
to miss-islington/cpython
that referenced
this issue
Feb 21, 2024
…ythonGH-115400) Doc/library/xml.rst: Document CVE-2023-52425 under "XML vulnerabilities" (cherry picked from commit fbd40ce) Co-authored-by: Sebastian Pipping <sebastian@pipping.org>
miss-islington
pushed a commit
to miss-islington/cpython
that referenced
this issue
Feb 21, 2024
…ythonGH-115400) Doc/library/xml.rst: Document CVE-2023-52425 under "XML vulnerabilities" (cherry picked from commit fbd40ce) Co-authored-by: Sebastian Pipping <sebastian@pipping.org>
miss-islington
pushed a commit
to miss-islington/cpython
that referenced
this issue
Feb 21, 2024
…ythonGH-115400) Doc/library/xml.rst: Document CVE-2023-52425 under "XML vulnerabilities" (cherry picked from commit fbd40ce) Co-authored-by: Sebastian Pipping <sebastian@pipping.org>
miss-islington
pushed a commit
to miss-islington/cpython
that referenced
this issue
Feb 21, 2024
…ythonGH-115400) Doc/library/xml.rst: Document CVE-2023-52425 under "XML vulnerabilities" (cherry picked from commit fbd40ce) Co-authored-by: Sebastian Pipping <sebastian@pipping.org>
miss-islington
pushed a commit
to miss-islington/cpython
that referenced
this issue
Feb 21, 2024
…ythonGH-115400) Doc/library/xml.rst: Document CVE-2023-52425 under "XML vulnerabilities" (cherry picked from commit fbd40ce) Co-authored-by: Sebastian Pipping <sebastian@pipping.org>
This was referenced Feb 21, 2024
ambv
pushed a commit
that referenced
this issue
Feb 21, 2024
…GH-115400) (GH-115760) Doc/library/xml.rst: Document CVE-2023-52425 under "XML vulnerabilities" (cherry picked from commit fbd40ce) Co-authored-by: Sebastian Pipping <sebastian@pipping.org>
ambv
pushed a commit
that referenced
this issue
Feb 21, 2024
…GH-115400) (GH-115761) Doc/library/xml.rst: Document CVE-2023-52425 under "XML vulnerabilities" (cherry picked from commit fbd40ce) Co-authored-by: Sebastian Pipping <sebastian@pipping.org>
ambv
pushed a commit
that referenced
this issue
Feb 21, 2024
…GH-115400) (GH-115762) Doc/library/xml.rst: Document CVE-2023-52425 under "XML vulnerabilities" (cherry picked from commit fbd40ce) Co-authored-by: Sebastian Pipping <sebastian@pipping.org>
ambv
pushed a commit
that referenced
this issue
Feb 21, 2024
…H-115400) (GH-115764) Doc/library/xml.rst: Document CVE-2023-52425 under "XML vulnerabilities" (cherry picked from commit fbd40ce) Co-authored-by: Sebastian Pipping <sebastian@pipping.org>
ambv
pushed a commit
that referenced
this issue
Feb 21, 2024
…H-115400) (GH-115763) Doc/library/xml.rst: Document CVE-2023-52425 under "XML vulnerabilities" (cherry picked from commit fbd40ce) Co-authored-by: Sebastian Pipping <sebastian@pipping.org>
ambv
added a commit
that referenced
this issue
Feb 21, 2024
ambv
added a commit
that referenced
this issue
Feb 21, 2024
woodruffw
pushed a commit
to woodruffw-forks/cpython
that referenced
this issue
Mar 4, 2024
…ythonGH-115400) Doc/library/xml.rst: Document CVE-2023-52425 under "XML vulnerabilities"
diegorusso
pushed a commit
to diegorusso/cpython
that referenced
this issue
Apr 17, 2024
…ythonGH-115400) Doc/library/xml.rst: Document CVE-2023-52425 under "XML vulnerabilities"
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
Bug report
Bug description:
Hi! 👋
Please upgrade bundled Expat to 2.6.0 (e.g. for the fix to CVE-2023-52425).
The CPython issue for previous 2.5.0 was #98739 and the related merged pull request was #98742, in case you want to have a look. In particular comment #98742 (review) could be of help.
Thanks in advance!
CPython versions tested on:
3.8, 3.9, 3.10, 3.11, 3.12, 3.13, CPython main branch
Operating systems tested on:
Linux, macOS, Windows, Other
Linked PRs
The text was updated successfully, but these errors were encountered: