UbuntuUpdates.org

Package "python-xmltodict"

Name: python-xmltodict

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • Makes working with XML feel like you are working with JSON (Python 3)

Latest version: 0.13.0-1ubuntu0.24.04.1
Release: noble (24.04)
Level: updates
Repository: main

Links



Other versions of "python-xmltodict" in Noble

Repository Area Version
base main 0.13.0-1
security main 0.13.0-1ubuntu0.24.04.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 0.13.0-1ubuntu0.24.04.1 2025-09-17 07:07:15 UTC

  python-xmltodict (0.13.0-1ubuntu0.24.04.1) noble-security; urgency=medium

  * SECURITY UPDATE: XML Injection when inserting XML tags.
    - debian/patches/CVE-2025-9375-*.patch: Add checks for special characters
      in xmltodict.py.
    - CVE-2025-9375

 -- Hlib Korzhynskyy <email address hidden> Mon, 15 Sep 2025 16:39:32 -0230

CVE-2025-9375 XML Injection vulnerability in xmltodict allows Input Data Manipulation. This issue affects xmltodict: from 0.14.2 before 0.15.1.



About   -   Send Feedback to @ubuntu_updates