Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

expose expat XML billion laughs attack mitigation APIs #90949

Open
gpshead opened this issue Feb 18, 2022 · 2 comments
Open

expose expat XML billion laughs attack mitigation APIs #90949

gpshead opened this issue Feb 18, 2022 · 2 comments
Labels
3.11 only security fixes topic-XML type-feature A feature request or enhancement

Comments

@gpshead
Copy link
Member

gpshead commented Feb 18, 2022

BPO 46793
Nosy @gpshead, @hartwork, @corona10

Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.

Show more details

GitHub fields:

assignee = None
closed_at = None
created_at = <Date 2022-02-18.21:27:31.809>
labels = ['type-feature', '3.11']
title = 'expose expat XML billion laughs attack mitigation APIs'
updated_at = <Date 2022-02-25.02:16:52.654>
user = 'https://github.com/gpshead'

bugs.python.org fields:

activity = <Date 2022-02-25.02:16:52.654>
actor = 'sping'
assignee = 'none'
closed = False
closed_date = None
closer = None
components = []
creation = <Date 2022-02-18.21:27:31.809>
creator = 'gregory.p.smith'
dependencies = []
files = []
hgrepos = []
issue_num = 46793
keywords = []
message_count = 2.0
messages = ['413513', '413955']
nosy_count = 3.0
nosy_names = ['gregory.p.smith', 'sping', 'corona10']
pr_nums = []
priority = 'normal'
resolution = None
stage = 'needs patch'
status = 'open'
superseder = None
type = 'enhancement'
url = 'https://bugs.python.org/issue46793'
versions = ['Python 3.11']

@gpshead
Copy link
Member Author

gpshead commented Feb 18, 2022

Quoting from #31397 (comment)

"""
XML_SetBillionLaughsAttackProtectionActivationThreshold

XML_SetBillionLaughsAttackProtectionMaximumAmplification

I still hope that someone can make those two^^ accessible (with additional glue code) to the user on pyexpat level in CPython.
""" - Sebastian Pipping @hartwork

@gpshead gpshead added 3.11 only security fixes type-feature A feature request or enhancement labels Feb 18, 2022
@hartwork
Copy link
Mannequin

hartwork mannequin commented Feb 25, 2022

First mention at https://bugs.python.org/issue44394#msg395642

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
3.11 only security fixes topic-XML type-feature A feature request or enhancement
Projects
None yet
Development

No branches or pull requests

2 participants