Skip to content

Upgrade bundled Expat to 2.8.2 (e.g. for the fix to CVE-2026-56132 and 12 others) #152216

Description

@hartwork

Please see blog post https://blog.hartwork.org/posts/expat-2-8-2-released/ for an overview and the change log at https://github.com/libexpat/libexpat/blob/R_2_8_2/expat/Changes for details. Affects all alive branches of Python. Thank you!

PS: Note that this release comes with three new files files to be bundled:

  • lib/fallthrough.h
  • lib/memory_sanitizer.h
  • lib/xcsinc.c

Related: #149698 (predecessor for Expat 2.8.1)

CC @StanFromIreland


Linked PRs

Metadata

Metadata

Labels

3.10only security fixes3.11only security fixes3.12only security fixes3.13bugs and security fixes3.14bugs and security fixes3.15pre-release feature fixes, bugs and security fixes3.16new features, bugs and security fixesextension-modulesC modules in the Modules dirtopic-XMLtype-securityA security issue
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions