Petl Project maintains a Python data-transformation library with a narrow vulnerability surface centered on its core ETL product. The observed exposure involves XML injection vulnerabilities arising from unsafe XPath evaluation in data-processing workflows. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Petl Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-29128CRITICAL petl before 1.68, in some configurations, allows resolution of entities in an XML document. | Nov 26, 2020 | 9.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Petl Project.
Media articles that mention a CVE ID that affects a product developed by Petl Project — matched by CVE ID, not by vendor name.