—
PYSEC-2026-924
SOAPpy vulnerable to XML External Entity attacks
Details
SOAPpy 0.12.5 allows remote attackers to read arbitrary files via a SOAP request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/soappy
Introduced in:
0No fixed version published yet for soappy (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2014-3242[ADVISORY]
- https://github.com/kiorky/soappy[PACKAGE]
- https://web.archive.org/web/20150501220613/http://www.pnigos.com/?p=260[WEB]
- https://web.archive.org/web/20200229062311/http://www.securityfocus.com/bid/67216[WEB]
- http://seclists.org/fulldisclosure/2014/May/20[WEB]
- http://www.openwall.com/lists/oss-security/2014/05/06/1[WEB]
- http://www.openwall.com/lists/oss-security/2014/05/06/9[WEB]
- https://pypi.org/project/soappy[PACKAGE]
- https://github.com/advisories/GHSA-52wr-3vww-rmpq[ADVISORY]