Repository navigation
Upgrade bundled Expat to 2.8.0 (e.g. for the fix to CVE-2026-41080) #149017
Copy link
Copy link
Closed
Labels
3.10 (EOL)end of lifeend of life3.11only security fixesonly security fixesextension-modulesC modules in the Modules dirC modules in the Modules dirrelease-blockertopic-XMLtype-securityA security issueA security issue
Description
Activity
- addedtype-securityA security issueA security issueextension-modulesC modules in the Modules dirC modules in the Modules dir
on Apr 26, 2026 Oh you beat me this time! ;-)
Reacted by Sebastian Pipping- added3.11only security fixesonly security fixes3.10 (EOL)end of lifeend of life3.12only security fixesonly security fixes3.13only security fixesonly security fixes3.14bugs and security fixesbugs and security fixes3.15bugs and security fixesbugs and security fixes
on Apr 26, 2026 7 remaining items
I there some intention that I may be missing?
The #146605 hasn't been merged yet so it can't be created.
@StanFromIreland that makes sense — thank you! 👍
- changed the title
[-][security] Please upgrade bundled Expat to 2.8.0 (e.g. for the fix to CVE-2026-41080)[/-][+][security] Upgrade bundled Expat to 2.8.0 (e.g. for the fix to CVE-2026-41080)[/+]on May 11, 2026 - changed the title
[-][security] Upgrade bundled Expat to 2.8.0 (e.g. for the fix to CVE-2026-41080)[/-][+]Upgrade bundled Expat to 2.8.0 (e.g. for the fix to CVE-2026-41080)[/+]on May 11, 2026 - moved this from In Progress to Done in Release and Deferred blockers 🚫
on Aug 10, 2026 @StanFromIreland the labels "3.10" and "3.11" look like leftovers here now. Is that true or intended to be and remain like that? I'm curious.
Once the issue is closed it doesn’t really matter to be honest.
@StanFromIreland I see, thanks for your reply!
Metadata
Metadata
Assignees
Labels
3.10 (EOL)end of lifeend of life3.11only security fixesonly security fixesextension-modulesC modules in the Modules dirC modules in the Modules dirrelease-blockertopic-XMLtype-securityA security issueA security issue
Projects
- StatusShow more project fieldsDone
Please see blog post https://blog.hartwork.org/posts/expat-2-8-0-released/ for an overview and the change log at https://github.com/libexpat/libexpat/blob/R_2_8_0/expat/Changes for details. Affects all alive branches of Python. Thank you!
Related: #146083 (predecessor for Expat 2.7.5)
Linked PRs