Skip to content

[3.12] gh-90949: expose Expat API to tune exponential expansion protections (GH-139368) - #151401

Merged
Yhg1s merged 1 commit into
python:3.12from
StanFromIreland:backport-19bc391-3.12
Aug 4, 2026
Merged

[3.12] gh-90949: expose Expat API to tune exponential expansion protections (GH-139368)#151401
Yhg1s merged 1 commit into
python:3.12from
StanFromIreland:backport-19bc391-3.12

Conversation

@StanFromIreland

@StanFromIreland StanFromIreland commented Jun 12, 2026

Copy link
Copy Markdown
Member

Expose the XML Expat 2.7.2 APIs to tune protections against "billion laughs" [1] attacks.

The exposed APIs are available on Expat parsers, that is, parsers created by xml.parsers.expat.ParserCreate(), as:

  • parser.SetBillionLaughsAttackProtectionActivationThreshold(threshold), and
  • parser.SetBillionLaughsAttackProtectionMaximumAmplification(max_factor).

This completes the work in f04bea4, and improves the existing related documentation.

[1]: https://en.wikipedia.org/wiki/Billion_laughs_attack (cherry picked from commit 6661123) (cherry picked from commit 19bc391)

… protections (pythonGH-139368)

Expose the XML Expat 2.7.2 APIs to tune protections against
"billion laughs" [1] attacks.

The exposed APIs are available on Expat parsers, that is,
parsers created by `xml.parsers.expat.ParserCreate()`, as:

- `parser.SetBillionLaughsAttackProtectionActivationThreshold(threshold)`, and
- `parser.SetBillionLaughsAttackProtectionMaximumAmplification(max_factor)`.

This completes the work in f04bea4,
and improves the existing related documentation.

[1]: https://en.wikipedia.org/wiki/Billion_laughs_attack
(cherry picked from commit 6661123)
(cherry picked from commit 19bc391)

Co-authored-by: Stan Ulbrych <stan@python.org>
Co-authored-by: Bénédikt Tran <10796600+picnixz@users.noreply.github.com>

@picnixz picnixz left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. But I can't merge it anyway.

@picnixz

picnixz commented Jul 4, 2026

Copy link
Copy Markdown
Member

Why was it a manual backport btw?

@StanFromIreland

Copy link
Copy Markdown
Member Author

I don't remember any more, it has been a while. Possibly the generated clinic or test decorators.

@Yhg1s
Yhg1s merged commit db195e3 into python:3.12 Aug 4, 2026
30 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants