untangle

condav1.1.1

Convert XML documents into Python objects.

License MITpermissive1 versions1 maintainers0 deps24 weekly dl
34
/ 100
Health
update required

[email protected] has vulnerabilities — update to latest

Update to >= 1.2.1 to fix known vulnerabilities

  • Low health score (34/100)
  • 2 high severity vulnerabilities
Health breakdown0 – 100
5/25
maintenance
0/20
popularity
15/25
security
12/15
maturity
2/15
community
Vulnerabilities
4
2 high2 low
Advisories (4)
SeverityIDSummaryFixed in
highCVE-2022-33977untangle vulnerable to XML Entity Expansion1.2.1
highCVE-2022-31471untangle vulnerable to Improper Restriction of XML External Entity Reference1.2.1
unknownCVE-2022-33977untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts recursive entity references in DTDs. By exploiting this vulnerability, a remote unauthenticated attacker may cause a denial-of-service (DoS) condition on the server where the product is running.1.2.1
unknownCVE-2022-31471untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts XML external entity references. By exploiting this vulnerability, a remote unauthenticated attacker may read the contents of local files.1.2.1

Health History

Dependency Tree

License Audit

API access

Get this data programmatically — free, no authentication.

curl https://depscope.dev/api/check/conda/untangle

First published · 2020-06-30 01:01:00.992000+00:00

Last updated · 2025-04-22 14:57:29.173000+00:00

untangle — Health Score 34/100 | DepScope