QID 981040
QID 981040: Python (pip) Security Update for feedparser (GHSA-hjf3-r7gw-9rwg)
Universal Feed Parser (aka feedparser or python-feedparser) before 5.1.2 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML ENTITY declaration in a non-ASCII encoded document.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-hjf3-r7gw-9rwg for updates pertaining to this vulnerability.
Vendor References
- GHSA-hjf3-r7gw-9rwg -
github.com/advisories/GHSA-hjf3-r7gw-9rwg
CVEs related to QID 981040
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-hjf3-r7gw-9rwg | feedparser |
|