CVE-2020-26709 describes an XML External Entity (XXE) Injection vulnerability in py-xml v1.0, allowing attackers to execute arbitrary code through a specially crafted XML file. This high-severity vulnerability (CVSS 7.5) has a low attack complexity and requires no user interaction, potentially leading to a complete loss of availability. While no active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion has been observed, the underlying CWE-611 indicates a known attack vector. The vulnerability is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:py-xml_project:py-xml:1.0:*:*:*:*:python:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.