Skip to content

Upgrade bundled Expat to 2.7.2 (e.g. for the fix to CVE-2025-59375)Β #138998

@hartwork

Description

@hartwork

Bug report

Bug description:

Hi! πŸ‘‹

Please upgrade bundled Expat to 2.7.2 (e.g. for the fix to CVE-2025-59375).

The CPython issue for previous 2.7.1 was #131809 and the related merged main pull request was #132192, in case you want to have a look. (The Dockerfile from comment #123689 (review) could be of help with raising confidence in a bump pull request when going forward.)

Thanks in advance!

CC @sethmlarson @gpshead

CPython versions tested on:

3.9, 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, CPython main branch

Operating systems tested on:

Linux, macOS, Windows, Other

Linked PRs

Metadata

Metadata

Assignees

No one assigned

    Projects

    Status

    Done

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions