CVE-2025-9375

EUVD-2025-26350
XML Injection vulnerability in xmltodict allows Input Data Manipulation.
This issue affects xmltodict: from 0.14.2 before 0.15.1.

NOTE: the scope of this CVE is disputed by the vendor on the grounds that xmltodict.unparse() delegates element-name handling to Python's xml.sax.saxutils.XMLGenerator, and that XMLGenerator should be the component performing validation.
aka Blind XPath Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 37.34%
Debian logo
Debian Releases
Debian Product
Codename
python-xmltodict
bookworm
0.13.0-1.1~deb12u1
fixed
bullseye
postponed
forky
1.0.3-1.1
fixed
sid
1.0.3-1.1
fixed
trixie
0.13.0-1.1~deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python-xmltodict
bionic
Fixed 0.11.0-1ubuntu0.1~esm1
released
focal
Fixed 0.12.0-1ubuntu0.1~esm1
released
jammy
Fixed 0.12.0-2ubuntu0.1~esm1
released
noble
Fixed 0.13.0-1ubuntu0.24.04.1
released
plucky
Fixed 0.13.0-1ubuntu0.25.04.1
released
questing
Fixed 0.13.0-1ubuntu1
released
resolute
Fixed 0.13.0-1ubuntu1
released
xenial
Fixed 0.9.2-3ubuntu0.1~esm1
released