$npx skillfedfor your agent

defusedxml

XML bomb protection for Python stdlib modules

Worth itPyPI XMLReleased Mar 2021241.2M downloads / moPSFLPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — defusedxml-0.7.1-py2.py3-none-any.whl
v0.7.1 · released 2021-03-08 · Python >=2.7, !=3.0.*, !=3.1.*, !=3.2.*, !=3.3.*, !=3.4.*

Yes. Defusedxml is a straightforward, zero-dependency security fix for a well-known class of XML parsing attacks. Install it if your application parses any XML from untrusted sources. The dormant maintenance status is not a concern; the vulnerabilities it addresses are decades old and stable. No known CVEs are recorded against it.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Low install friction with no runtime dependencies.
  • Maintenance is dormant—last release was in March 2021 and last commit in September 2024—but the package is marked Production/Stable and has been stable since its 2013 release, suggesting the attack vectors it addresses are well-understood and unlikely to require frequent updates.

License · maintenance · safety

PSFL (permissive) — Licensed under the Python Software Foundation License (PSFL), a permissive license. No restrictions on commercial or private use; you may modify and redistribute under the same terms.

last release 2021-03-08 (1985 days) · last repo commit 2024-09-03 · 550 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 241,198,654 downloads/mo, #163 on PyPI

Verify before relying

import defusedxml.ElementTree as ET

# Parse XML safely
tree = ET.parse('file.xml')
root = tree.getroot()
  • Whether defusedxml's protections remain effective against newly discovered XML parsing vulnerabilities not documented in the 2021 release.
  • Compatibility with Python versions beyond 3.9 (classifiers list only up to 3.9; current support unclear).
Same gist for agents: .md · .json

What it is and what it does

Defusedxml is a security-hardened wrapper around Python's standard XML parsing libraries (ElementTree, minidom, SAX, pulldom, and xmlrpc). It addresses a family of XML parsing vulnerabilities—billion laughs attacks, quadratic blowup entity expansion, external entity expansion (both remote and local file), and DTD retrieval—by disabling dangerous features like entity expansion and external entity resolution that are enabled by default in the standard library but rarely needed in practice.

The package provides drop-in replacements for the standard library modules. It has no runtime dependencies and installs cleanly. Maintenance is dormant but the underlying attack vectors are well-established and unlikely to change, making the package suitable for applications that parse untrusted XML and need straightforward protection without external dependencies.

Use it for

  • Parse XML from untrusted sources (user uploads, external APIs) without risking memory exhaustion or CPU DoS from entity expansion bombs.
  • Harden applications using Python's standard XML libraries by swapping imports to defusedxml equivalents.
  • Protect XML-RPC services from gzip bomb and entity expansion attacks without rewriting the service layer.
  • Safely process SOAP or other XML-based protocols where the input is not fully under your control.
  • Meet security compliance requirements for XML parsing in applications handling sensitive data.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

Defusedxml is a straightforward, zero-dependency security fix for a well-known class of XML parsing attacks. Install it if your application parses any XML from untrusted sources. The dormant maintenance status is not a concern; the vulnerabilities it addresses are decades old and stable. No known CVEs are recorded against it.

Install

defusedxml on PyPI

Before you install

Low install friction with no runtime dependencies. Maintenance is dormant—last release was in March 2021 and last commit in September 2024—but the package is marked Production/Stable and has been stable since its 2013 release, suggesting the attack vectors it addresses are well-understood and unlikely to require frequent updates.

License in practice

Licensed under the Python Software Foundation License (PSFL), a permissive license. No restrictions on commercial or private use; you may modify and redistribute under the same terms.

Quickstart

import defusedxml.ElementTree as ET

# Parse XML safely
tree = ET.parse('file.xml')
root = tree.getroot()

Verify before relying

  • Whether defusedxml's protections remain effective against newly discovered XML parsing vulnerabilities not documented in the 2021 release.
  • Compatibility with Python versions beyond 3.9 (classifiers list only up to 3.9; current support unclear).

Package facts

LicensePSFL permissive
Python supportSupports the current Python release >=2.7, !=3.0.*, !=3.1.*, !=3.2.*, !=3.3.*, !=3.4.*
Install frictionLow. Pure-Python wheel
Runtime dependenciesNone
MaintenanceDormant 1,985 days since the last release
Last repo commit
First released
Downloads241,198,654 / month, #163 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: Python Software Foundation LicenseNatural Language :: EnglishProgramming Language :: PythonProgramming Language :: Python :: 2Programming Language :: Python :: 2.7Programming Language :: Python :: 3Programming Language :: Python :: 3.5Programming Language :: Python :: 3.6Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Topic :: Text Processing :: Markup :: XML

Evidence: defusedxml-0.7.1-py2.py3-none-any.whl

Tags

Capabilities
XML bomb protectionXML security hardeningentity expansion defensesafe XML parsingXXE attack preventionXML DoS mitigationdefused XML parser
Topics
xml-securitydos-protection
PyPI keywords
xmlbombDoS

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “XML bomb protection”

  • defusedxmlDefusedxml hardens Python's standard XML libraries against XML bomb…
  • multimarkConverts Markdown to HTML, LaTeX, groff man, XML, or normalized…
  • pdfminerExtracts text and layout information from PDF documents, including…

Give your agent the search over MCP, or paste the wish link into any chat.

More XML packages

beautifulsoup4 Worth it
PyPI · Python Modules · released Jun 2026

Beautiful Soup parses HTML and XML documents into a navigable tree, providing Pythonic methods to search, iterate, and modify the parsed content.

Install it if you need to parse or extract data from markup documents.

MITpure Python · 3.7.0+
432.1Mdownloads / mo
lxml Worth it
PyPI · Python Modules · released May 2026

lxml provides Python bindings to libxml2 and libxslt, enabling parsing, validation, and transformation of XML and HTML documents through an ElementTree-compatible API with support for XPath, XSLT, and schema validation.

Install it if you need robust XML/HTML parsing, validation, or transformation; avoid it only if you must stay pure-Python and can accept slower performance.

permissive licensecompiled wheel · 3.8+
416.8Mdownloads / mo
docutils With conditions
PyPI · Software Development · released May 2026

Docutils converts plaintext documentation in reStructuredText format into multiple output formats including HTML, XML, and LaTeX using a modular processing system.

BSD-3-Clausepure Python · 3.9+
225.6Mdownloads / mo
xmltodict Worth it
PyPI · XML · released Feb 2026

Converts XML to Python dictionaries and back, treating XML parsing and generation like working with JSON.

MITpure Python · 3.9+
127.1Mdownloads / mo
Sphinx Worth it
PyPI · Software Development · released Dec 2025

Sphinx generates professional documentation from reStructuredText source files, producing HTML, PDF, EPUB, and other formats with automatic cross-references, code highlighting, and hierarchical navigation.

BSD-2-Clausepure Python · 3.12+
91.8Mdownloads / mo
feedparser Worth it
PyPI · Python Modules · released Jul 2026

Parses Atom and RSS feeds (including RSS 0.9x, RSS 1.0, RSS 2.0, CDF, Atom 0.3, and Atom 1.0) into Python data structures.

Install it if you need to consume RSS or Atom feeds.

permissive licensepure Python · 3.10+
20.3Mdownloads / mo

See also types-defusedxml · djangorestframework-xml · tree-sitter-xml · xacro · xsdata · meld3 · xmlunittest · et-xmlfile · xmldiff