Linux workstation

Upstream software project

python-defusedxml

XML bomb protection for Python stdlib modules

About python-defusedxml

XML bomb protection for Python stdlib modules

This project links 5 native package records across 3 recorded operating-system releases. Compare the retained versions and architectures below, then open the package for your own release.

These are catalog observations, not a guarantee of installation, compatibility, or upstream support.

Project pictures and package coverage

openSUSE Leap 15.6: 2 package records; openSUSE Leap 16.0: 1 package records; openSUSE Tumbleweed: 2 package records. Catalog coverage diagram, not an application screenshot.python-defusedxml: recorded package coverageopenSUSE Leap 15.62 recordsopenSUSE Leap 16.01 recordsopenSUSE Tumbleweed2 records
OpenFactory diagram of linked package records. It is not an application screenshot.

Project identity

Project
python-defusedxml
Publisher
Not authoritatively mapped
Native package records
5
Operating systems
opensuse-leap-15-6, opensuse-leap-16-0, opensuse-tumbleweed
License expression
Python-2.0
Metadata completeness
100/100 (not a software quality rating)
Source repository
Not reported

Source-reported description

The fullest retained description is shown with its source. Distribution packaging descriptions may include downstream details.

The results of an attack on a vulnerable XML library can be fairly dramatic. With just a few hundred bytes of XML data an attacker can occupy several gigabytes of memory within seconds. An attacker can also keep CPUs busy for a long time with a small to medium size request. This library allows for XML to be parsed in a manner that avoids these pitfalls.

Description source

Packages by operating system

Compare recorded versions, then open a package for dependency, file, checksum, and repository evidence. Version strings are distribution-specific, not a ranking of newer software.

openSUSE Leap 15.6

  1. python311-defusedxml

    openSUSE Leap 15.6 / Development/Languages/Python / source python-defusedxml

    0.7.1-150400.7.3.8

    XML bomb protection for Python stdlib modules

    noarchleap-15.6
  2. python3-defusedxml

    openSUSE Leap 15.6 / Development/Languages/Python / source python-defusedxml

    0.6.0-1.42

    XML bomb protection for Python stdlib modules

    noarchleap-15.6

openSUSE Leap 16.0

  1. python313-defusedxml

    openSUSE Leap 16.0 / Development/Languages/Python / source python-defusedxml

    0.7.1-160000.2.2

    XML bomb protection for Python stdlib modules

    noarchleap-16.0

openSUSE Tumbleweed

  1. python313-defusedxml

    openSUSE Tumbleweed / Development/Languages/Python / source python-defusedxml

    0.7.1-4.4

    XML bomb protection for Python stdlib modules

    noarchtumbleweed
  2. python314-defusedxml

    openSUSE Tumbleweed / Development/Languages/Python / source python-defusedxml

    0.7.1-4.4

    XML bomb protection for Python stdlib modules

    noarchtumbleweed

Project resources and further reading

Mapping provenance

Only source-backed identity signals create public cross-OS links. A reviewer can later approve or dispute an inferred relationship without rewriting native package history.

No field-level source record is published yet.

python-defusedxml Software and Packages | OpenFactory