Skip to content

[security] Please upgrade bundled Expat to 2.7.4 (e.g. for the fixes to CVE-2026-24515 and CVE-2026-25210) #144363

@hartwork

Description

@hartwork

Bug report

Bug description:

Hello! 👋

Please upgrade bundled Expat to 2.7.4 (e.g. for the fixes to CVE-2026-24515 and CVE-2026-25210).

The CPython issue for previous 2.7.3 was #139312 and the related merged main pull request was #139319, in case you want to have a look. (The Dockerfile from comment #123689 (review) could be of help with raising confidence in a bump pull request when going forward.)

Thanks in advance!

CPython versions tested on:

3.9, 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, CPython main branch

Operating systems tested on:

Linux, macOS, Windows, Other

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions