FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

[3.11] gh-90949: expose Expat API to tune exponential expansion protections (GH-139368) (GH-151401) by StanFromIreland · Pull Request #155346 · python/cpython · GitHub

/ cpython Public

[3.11] gh-90949: expose Expat API to tune exponential expansion protections (GH-139368) (GH-151401) - #155346

Merged
pablogsal merged 2 commits into
python:3.11from
StanFromIreland:backport-db195e3-3.11
Aug 9, 2026
Merged

[3.11] gh-90949: expose Expat API to tune exponential expansion protections (GH-139368) (GH-151401)#155346
pablogsal merged 2 commits into
python:3.11from
StanFromIreland:backport-db195e3-3.11

Conversation

StanFromIreland commented Aug 7, 2026
edited by bedevere-app Bot
Loading

Copy link
Copy Markdown
Member

Expose the XML Expat 2.7.2 APIs to tune protections against "billion laughs" [1] attacks.

The exposed APIs are available on Expat parsers, that is, parsers created by xml.parsers.expat.ParserCreate(), as:

  • parser.SetBillionLaughsAttackProtectionActivationThreshold(threshold), and
  • parser.SetBillionLaughsAttackProtectionMaximumAmplification(max_factor).

This completes the work in f04bea4, and improves the existing related documentation.

[1]: https://en.wikipedia.org/wiki/Billion_laughs_attack (cherry picked from commit 6661123) (cherry picked from commit 19bc391) (cherry picked from commit db195e3)

… protections (pythonGH-139368) (pythonGH-151401)

Expose the XML Expat 2.7.2 APIs to tune protections against
"billion laughs" [1] attacks.

The exposed APIs are available on Expat parsers, that is,
parsers created by `xml.parsers.expat.ParserCreate()`, as:

- `parser.SetBillionLaughsAttackProtectionActivationThreshold(threshold)`, and
- `parser.SetBillionLaughsAttackProtectionMaximumAmplification(max_factor)`.

This completes the work in f04bea4,
and improves the existing related documentation.

[1]: https://en.wikipedia.org/wiki/Billion_laughs_attack
(cherry picked from commit 6661123)
(cherry picked from commit 19bc391)
(cherry picked from commit db195e3)

Co-authored-by: Stan Ulbrych <stan@python.org>
Co-authored-by: Bénédikt Tran <10796600+picnixz@users.noreply.github.com>

Copy link
Copy Markdown
Member Author

The only conflict was in the generated AC.

pablogsal merged commit 3c1801a into python:3.11 Aug 9, 2026
33 of 37 checks passed
StanFromIreland deleted the backport-db195e3-3.11 branch August 9, 2026 18:19
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants


Back | FazBrowse Home | New Git URL