| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Sorry, something went wrong.
CVE-2025-59375) (pythonGH-139234) Expose the XML Expat 2.7.2 mitigation APIs to disallow use of disproportional amounts of dynamic memory from within an Expat parser (see CVE-2025-59375 for instance). The exposed APIs are available on Expat parsers, that is, parsers created by `xml.parsers.expat.ParserCreate()`, as: - `parser.SetAllocTrackerActivationThreshold(threshold)`, and - `parser.SetAllocTrackerMaximumAmplification(max_factor)`. (cherry picked from commit f04bea4) Co-authored-by: Bénédikt Tran <10796600+picnixz@users.noreply.github.com>
…on API (python#139366) Fix some typos left in f04bea4, and simplify some internal functions to ease maintenance of future mitigation APIs. (cherry picked from commit 68a1778)
|
To have a good synchronization, we'll also delay 3.10 to 3.13 backports for their next release cycle (see #139359 (comment)). |
Sorry, something went wrong.
|
I set DO-NOT-MERGE to avoid confusion. Unset that when you think we should be releasing this. |
Sorry, something went wrong.
There was a problem hiding this comment.
The 22 additional lines are in the clinic file so all good.
Sorry, something went wrong.
|
@Yhg1s do you have a minute for this? 🙏 |
Sorry, something went wrong.
|
@Yhg1s do you have a minute? 🙏 |
Sorry, something went wrong.
|
Thanks! 🙏 |
Sorry, something went wrong.
| Back | FazBrowse Home | New Git URL |
Expose the XML Expat 2.7.2 mitigation APIs to disallow use of disproportional amounts of dynamic memory from within an Expat parser (see CVE-2025-59375 for instance).
The exposed APIs are available on Expat parsers, that is, parsers created by xml.parsers.expat.ParserCreate(), as:
(cherry picked from commit f04bea4)
CC @picnixz
📚 Documentation preview 📚: https://cpython-previews--139527.org.readthedocs.build/