Skip to content

Conversation

@sethmlarson
Copy link
Contributor

@sethmlarsonsethmlarson commented Feb 15, 2024

Feeding the parser by too small chunks defers parsing to prevent CVE-2023-52425. Future versions of Expat may be more reactive. (cherry picked from commit 4a08e7b)

…ythonGH-115164) Feeding the parser by too small chunks defers parsing to prevent CVE-2023-52425. Future versions of Expat may be more reactive. (cherry picked from commit 4a08e7b) Co-authored-by: Serhiy Storchaka <storchaka@gmail.com>
@sethmlarson
Copy link
ContributorAuthor

Marked as release blocker as it blocks #115475

@ambvambv merged commit 366f315 into python:3.8Feb 21, 2024
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

release-blockertestsTests in the Lib/test dir

Projects

Development

Successfully merging this pull request may close these issues.

3 participants

@sethmlarson@ambv@serhiy-storchaka