VDB
Sign up
—

PYSEC-2026-923

SOAPpy vulnerable to XXE attacks

Quick fix

PYSEC-2026-923 — soappy: upgrade to the fixed version with the command below.

pip install --upgrade 'soappy>=0.12.6'

Details

SOAPpy 0.12.5 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted SOAP request containing a large number of nested entity references.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/soappy
Introduced in: 0Fixed in: 0.12.6
Fixpip install --upgrade 'soappy>=0.12.6'

References