Skip to content

Conversation

@hartwork
Copy link
Contributor

@hartwork hartwork commented Nov 26, 2025

Copy link
Member

@vstinner vstinner left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@gpshead gpshead added needs backport to 3.13 bugs and security fixes needs backport to 3.14 bugs and security fixes labels Nov 29, 2025
@gpshead gpshead moved this from Todo to In Progress in Docs PRs Nov 29, 2025
@gpshead gpshead merged commit 440bcb9 into python:main Nov 29, 2025
41 checks passed
@miss-islington-app
Copy link

Thanks @hartwork for the PR, and @gpshead for merging it 🌮🎉.. I'm working now to backport this PR to: 3.13, 3.14.
🐍🍒⛏🤖

@github-project-automation github-project-automation bot moved this from In Progress to Done in Docs PRs Nov 29, 2025
miss-islington pushed a commit to miss-islington/cpython that referenced this pull request Nov 29, 2025
…ature `xml.sax.handler.feature_external_ges` (pythonGH-141996)

Doc/library/xml.sax.handler.rst: Warn of XXE with feature_external_ges

Related to commit baa9f33
(cherry picked from commit 440bcb94560937888cd9bcb28a138acc2c6a6cbc)

Co-authored-by: Sebastian Pipping <sebastian@pipping.org>
@bedevere-app
Copy link

bedevere-app bot commented Nov 29, 2025

GH-142072 is a backport of this pull request to the 3.14 branch.

@bedevere-app bedevere-app bot removed the needs backport to 3.14 bugs and security fixes label Nov 29, 2025
miss-islington pushed a commit to miss-islington/cpython that referenced this pull request Nov 29, 2025
…ature `xml.sax.handler.feature_external_ges` (pythonGH-141996)

Doc/library/xml.sax.handler.rst: Warn of XXE with feature_external_ges

Related to commit baa9f33
(cherry picked from commit 440bcb9)

Co-authored-by: Sebastian Pipping <sebastian@pipping.org>
@bedevere-app
Copy link

bedevere-app bot commented Nov 29, 2025

GH-142073 is a backport of this pull request to the 3.13 branch.

@bedevere-app bedevere-app bot removed the needs backport to 3.13 bugs and security fixes label Nov 29, 2025
gpshead pushed a commit that referenced this pull request Nov 29, 2025
…eature `xml.sax.handler.feature_external_ges` (GH-141996) (#142072)

gh-141994: Warn of XXE vulnerability in documentation of SAX feature `xml.sax.handler.feature_external_ges` (GH-141996)

Doc/library/xml.sax.handler.rst: Warn of XXE with feature_external_ges

Related to commit baa9f33
(cherry picked from commit 440bcb9)

Co-authored-by: Sebastian Pipping <sebastian@pipping.org>
gpshead pushed a commit that referenced this pull request Nov 29, 2025
…eature `xml.sax.handler.feature_external_ges` (GH-141996) (#142073)

gh-141994: Warn of XXE vulnerability in documentation of SAX feature `xml.sax.handler.feature_external_ges` (GH-141996)

Doc/library/xml.sax.handler.rst: Warn of XXE with feature_external_ges

Related to commit baa9f33
(cherry picked from commit 440bcb9)

Co-authored-by: Sebastian Pipping <sebastian@pipping.org>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

docs Documentation in the Doc dir

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

3 participants