VDB
Sign up
MEDIUM5.0

PYSEC-2026-1765

Peppol-py is vulnerable to XXE attacks due to Saxon configuration

Quick fix

PYSEC-2026-1765 — peppol-py: upgrade to the fixed version with the command below.

pip install --upgrade 'peppol-py>=1.1.1'

Details

Peppol-py before 1.1.1 allows XXE attacks because of the Saxon configuration. When validating XML-based invoices, the XML parser could read files from the filesystem and expose their content to a remote host.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/peppol-py
Introduced in: 0Fixed in: 1.1.1
Fixpip install --upgrade 'peppol-py>=1.1.1'

References