Repository navigation
Upgrade bundled Expat to 2.8.1 (e.g. for the fix to CVE-2026-45186) #149698
Copy link
Copy link
Closed
Labels
3.10 (EOL)end of lifeend of life3.11only security fixesonly security fixes3.12only security fixesonly security fixesextension-modulesC modules in the Modules dirC modules in the Modules dirtopic-XMLtype-securityA security issueA security issue
Description
Activity
- addedtype-securityA security issueA security issueextension-modulesC modules in the Modules dirC modules in the Modules dir3.11only security fixesonly security fixes3.10 (EOL)end of lifeend of life3.12only security fixesonly security fixes3.13only security fixesonly security fixes3.14bugs and security fixesbugs and security fixes3.15pre-release feature fixes, bugs and security fixespre-release feature fixes, bugs and security fixes3.16new features, bugs and security fixesnew features, bugs and security fixes
on May 11, 2026 - changed the title
[-][security] Please upgrade bundled Expat to 2.8.1 (e.g. for the fix to CVE-2026-45186)[/-][+][security] Upgrade bundled Expat to 2.8.1 (e.g. for the fix to CVE-2026-45186)[/+]on May 11, 2026 - changed the title
[-][security] Upgrade bundled Expat to 2.8.1 (e.g. for the fix to CVE-2026-45186)[/-][+]Upgrade bundled Expat to 2.8.1 (e.g. for the fix to CVE-2026-45186)[/+]on May 11, 2026 4 remaining items
- addedneeds backport to 3.12only security fixesonly security fixesand removedneeds backport to 3.12only security fixesonly security fixes
on May 18, 2026 - removed3.13only security fixesonly security fixes3.14bugs and security fixesbugs and security fixes3.15pre-release feature fixes, bugs and security fixespre-release feature fixes, bugs and security fixes3.16new features, bugs and security fixesnew features, bugs and security fixes
on May 20, 2026 #146605 (2.7.5) and #150007 (3.12 backport of 2.8.0, #149017) are done, so I think this is no longer blocked :)
The issue is still open as the backport PRs #149074 and #149075 haven't been merged yet, so I haven't been able to open the backports. This could be a good place to test that new stacked PRs feature I think we've enabled.
Oh right, sorry! Yes, 3.12 backport isn't blocked, just 3.11 and 3.10 now.
Metadata
Metadata
Assignees
Labels
3.10 (EOL)end of lifeend of life3.11only security fixesonly security fixes3.12only security fixesonly security fixesextension-modulesC modules in the Modules dirC modules in the Modules dirtopic-XMLtype-securityA security issueA security issue
Please see blog post https://blog.hartwork.org/posts/expat-2-8-1-released/ for an overview and the change log at https://github.com/libexpat/libexpat/blob/R_2_8_1/expat/Changes for details. Affects all alive branches of Python. Thank you!
Related: #149017 (predecessor for Expat 2.8.0)
CC @StanFromIreland
CVE-2026-45186
Linked PRs