summaryrefslogtreecommitdiffstats
path: root/Doc/library/pyexpat.rst
diff options
context:
space:
mode:
authorChristian Heimes <christian@cheimes.de>2013-03-26 16:35:55 (GMT)
committerChristian Heimes <christian@cheimes.de>2013-03-26 16:35:55 (GMT)
commit7380a67267d9ec59b70617ea59ff31819f530942 (patch)
tree0648f9c8a5594f0c90ef45c9aefa43440ca7128a /Doc/library/pyexpat.rst
parent5be6d74a0d0ae111cd823d2b7a5896c77d8c8895 (diff)
downloadcpython-7380a67267d9ec59b70617ea59ff31819f530942.zip
cpython-7380a67267d9ec59b70617ea59ff31819f530942.tar.gz
cpython-7380a67267d9ec59b70617ea59ff31819f530942.tar.bz2
Issue 17538: Document XML vulnerabilties
Diffstat (limited to 'Doc/library/pyexpat.rst')
-rw-r--r--Doc/library/pyexpat.rst7
1 files changed, 7 insertions, 0 deletions
diff --git a/Doc/library/pyexpat.rst b/Doc/library/pyexpat.rst
index 861546c..420e407 100644
--- a/Doc/library/pyexpat.rst
+++ b/Doc/library/pyexpat.rst
@@ -14,6 +14,13 @@
references to these attributes should be marked using the :member: role.
+.. warning::
+
+ The :mod:`pyexpat` module is not secure against maliciously
+ constructed data. If you need to parse untrusted or unauthenticated data see
+ :ref:`xml-vulnerabilities`.
+
+
.. index:: single: Expat
The :mod:`xml.parsers.expat` module is a Python interface to the Expat