feedparser@4.1 vulnerabilities

Universal feed parser, handles RSS 0.9x, RSS 1.0, RSS 2.0, CDF, Atom 0.3, and Atom 1.0 feeds

Direct Vulnerabilities

Known vulnerabilities in the feedparser package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Cross-site Scripting (XSS)

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via Universal Feed Parser allows remote attackers to inject arbitrary web script or HTML via vectors involving nested CDATA stanzas.

How to fix Cross-site Scripting (XSS)?

Upgrade feedparser to version 5.0 or higher.

[,5.0)
  • M
Denial of Service (DoS)

feedparser is a Universal feed parser, handles RSS 0.9x, RSS 1.0, RSS 2.0, CDF, Atom 0.3, and Atom 1.0 feeds Universal Feed Parser (aka feedparser or python-feedparser) before 5.1.2 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML ENTITY declaration in a non-ASCII encoded document.

[,5.1.2]
  • M
Cross-site Scripting (XSS)

feedparser is a Universal feed parser, handles RSS 0.9x, RSS 1.0, RSS 2.0, CDF, Atom 0.3, and Atom 1.0 feeds.

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) attacks. Remote attackers may be able to inject arbitrary web script or HTML via an unexpected URI scheme, as demonstrated by a javascript: URI.

How to fix Cross-site Scripting (XSS)?

Upgrade feedparser to version 5.0.1 or higher.

[,5.0.1)
  • M
Denial of Service (DoS)

feedparser is a Universal feed parser, handles RSS 0.9x, RSS 1.0, RSS 2.0, CDF, Atom 0.3, and Atom 1.0 feeds.

Affected versions of this package are vulnerable to Denial of Service (DoS) attacks. Remote attackersmay be able to cause the application to crash by sending a malformed DOCTYPE declaration.

How to fix Denial of Service (DoS)?

Upgrade feedparser to version 5.0.1 or higher.

[,5.0.1)
  • M
Cross-site Scripting (XSS)

feedparser is a Universal feed parser, handles RSS 0.9x, RSS 1.0, RSS 2.0, CDF, Atom 0.3, and Atom 1.0 feeds.

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) attacks. Remote attackers may be able to inject arbitrary web script or HTML via malformed XML comments.

How to fix Cross-site Scripting (XSS)?

Upgrade feedparser to version 5.0.1 or higher.

[,5.0.1)