VDB
Sign up
—

PYSEC-2026-924

SOAPpy vulnerable to XML External Entity attacks

Details

SOAPpy 0.12.5 allows remote attackers to read arbitrary files via a SOAP request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/soappy
Introduced in: 0

No fixed version published yet for soappy (pip). Pin to a known-safe version or switch to an alternative.

References