-
-
Notifications
You must be signed in to change notification settings - Fork 34.6k
Upgrade bundled Expat to 2.8.1 (e.g. for the fix to CVE-2026-45186) #149698
Copy link
Copy link
Open
Labels
3.10only security fixesonly security fixes3.11only security fixesonly security fixes3.12only security fixesonly security fixes3.13bugs and security fixesbugs and security fixes3.14bugs and security fixesbugs and security fixes3.15pre-release feature fixes, bugs and security fixespre-release feature fixes, bugs and security fixes3.16new features, bugs and security fixesnew features, bugs and security fixesextension-modulesC modules in the Modules dirC modules in the Modules dirtopic-XMLtype-securityA security issueA security issue
Metadata
Metadata
Assignees
Labels
3.10only security fixesonly security fixes3.11only security fixesonly security fixes3.12only security fixesonly security fixes3.13bugs and security fixesbugs and security fixes3.14bugs and security fixesbugs and security fixes3.15pre-release feature fixes, bugs and security fixespre-release feature fixes, bugs and security fixes3.16new features, bugs and security fixesnew features, bugs and security fixesextension-modulesC modules in the Modules dirC modules in the Modules dirtopic-XMLtype-securityA security issueA security issue
Please see blog post https://blog.hartwork.org/posts/expat-2-8-1-released/ for an overview and the change log at https://github.com/libexpat/libexpat/blob/R_2_8_1/expat/Changes for details. Affects all alive branches of Python. Thank you!
Related: #149017 (predecessor for Expat 2.8.0)
CC @StanFromIreland
CVE-2026-45186
Linked PRs