defusedxml

Drop-in replacements for Python's XML modules that block XML-bomb and entity-expansion attacks

Library
PyPI
v0.7.1
554 stars
Custom / Unknown

Repository Health

Pre-computed score based on development activity, maintenance, community, maturity, and trend momentum. How we score it →
41 /100 Fair
Development Activity 0
Maintenance 20
Community 64
Maturity 60
Momentum 20

Technical Analysis

AI-assessed by reading the actual repository — architecture, code quality, innovation, and documentation. How we score it →
79 /100 Good
Architecture 75
Code Quality 82
Innovation 65
Learning Curve 92

defusedxml provides hardened drop-in replacements for Python’s standard-library XML parsing modules — xml.etree.ElementTree, xml.dom.minidom, xml.sax, xmlrpc, and lxml.etree — that disable or guard against the entity-expansion and external-entity vulnerabilities present in the defaults. Python’s built-in XML parsers are, by design, vulnerable to attacks like billion-laughs entity expansion, quadratic blowup, external entity (XXE) file disclosure, and DTD retrieval, none of which most application code is prepared to defend against.

Rather than requiring developers to hand-configure every parser’s security options correctly, defusedxml ships pre-configured, secure-by-default parser wrappers with the same API as the modules they replace, so switching a vulnerable import xml.etree.ElementTree as ET to import defusedxml.ElementTree as ET closes the relevant attack classes with a one-line change.

What You Get

  • defusedxml.ElementTree as a secure drop-in for xml.etree.ElementTree
  • defusedxml.minidom, defusedxml.sax, and defusedxml.pulldom secure equivalents of their stdlib counterparts
  • defusedxml.expatbuilder and defusedxml.expatreader for lower-level Expat-based parsing with entity protections
  • defusedxml.xmlrpc to monkey-patch Python’s xmlrpc client/server against XML attacks
  • defusedxml.lxml for adding the same protections when using the third-party lxml library
  • Clear, documented exceptions (EntitiesForbidden, ExternalReferenceForbidden, etc.) raised when an attack pattern is detected

Common Use Cases

  • Replacing unsafe stdlib XML parsing in any Python service that accepts XML from untrusted sources (uploads, APIs, SOAP)
  • Hardening SAML, RSS/Atom feed, or SOAP/XML-RPC processing pipelines against XXE and billion-laughs attacks
  • Passing security audits or compliance checks that flag raw xml.etree/xml.dom.minidom usage as a known vulnerability class
  • Safely parsing XML configuration or data files uploaded by end users in web applications

Under The Hood

Architecture The package is a set of thin, focused wrapper modules — common.py (85 lines) defines the shared DTDForbidden, EntitiesForbidden, and ExternalReferenceForbidden exception types plus the core _generate_etree_functions-style guarding logic, while each of ElementTree.py (188 lines), minidom.py, sax.py, pulldom.py, expatbuilder.py, expatreader.py, cElementTree.py, lxml.py, and xmlrpc.py reimplements just enough of its corresponding stdlib module’s public API to intercept parser construction and inject a secure Expat/lxml resolver that raises rather than expands dangerous constructs; __init__.py centralizes the package’s parse-and-raise convenience helpers. The design deliberately keeps each module’s surface area minimal and mirrors the stdlib API 1:1 so existing code needs only an import-path change to adopt it. Tech Stack Pure Python, zero required runtime dependencies (the lxml module is only exercised if the optional lxml package is already installed by the consumer), packaged with a standard setup.py/pyproject.toml. Code Quality tests.py at the repository root exercises each of the guarded parsers against a xmltestdata/ corpus of known attack payloads (entity bombs, external entity references, quadratic blowup), with CI historically run via Travis and coverage tracked via Codecov (badges in the README); the project also maintains a SECURITY.md documenting its threat model and disclosure process. API Design Because every module mirrors its stdlib counterpart’s function names and signatures exactly, the learning curve is close to zero — the entire integration is typically a single changed import line, with the tradeoff that some rarely-needed stdlib XML features are deliberately unavailable if they can’t be made safe.

Used by 15 apps in this directory

Python
59%
Apache 2.0

argilla

AI Development · Data Engineering

5,125

Collaborate on high-quality AI training data with a self-hosted annotation platform built for LLMs, NLP, and multimodal models.

View details
65
Repo Health
81
Technical
61
Dependency
Built with
Python 59%
Jupyter Notebook 21%
Updated 1 weeks ago
Python
55%
Other

authentik

Authentication · Security

25,758

The self-hosted Identity Provider that replaces Okta, Auth0, and Entra ID with a unified SSO platform supporting SAML, OAuth2/OIDC, LDAP, RADIUS, and WebAuthn.

View details
92
Repo Health
81
Technical
66
Dependency
Built with
Python 55%
TypeScript 36%
Updated 4 days ago
Python
51%
AGPL 3.0

Khoj

AI Assistants · Knowledge Management · Productivity

37,526

A self-hostable AI second brain that chats with your documents, searches the web, builds custom agents, and runs entirely on your own LLM.

View details
63
Repo Health
82
Technical
66
Dependency
Built with
Python 51%
TypeScript 36%
Updated 2 months ago
Python
86%
Apache 2.0

knowhere

AI Development · AI Memory · Developer Tools

3,541

Transform messy, unstructured documents into persistent, navigable memory that AI agents can actually use.

View details
82
Repo Health
75
Technical
66
Dependency
Built with
Python 86%
HTML 14%
Updated 1 weeks ago
TypeScript
39%
Apache 2.0

Label Studio

AI Development · Data Engineering

28,358

Label Studio is an open-source, multi-type data labeling platform that lets teams annotate images, text, audio, video, and time series data with a configurable XML-based UI and export annotations in formats ready for any ML framework.

View details
93
Repo Health
87
Technical
67
Dependency
Built with
TypeScript 39%
JavaScript 27%
Python 25%
Updated 4 days ago
Python
69%
MIT

Langflow

AI Agents · AI Development

155,319

Build, test, and deploy AI agents and RAG workflows visually with native API and MCP server export.

View details
90
Repo Health
85
Technical
65
Dependency
Built with
Python 69%
TypeScript 22%
Updated 4 days ago
Python
51%
AGPL 3.0

LearnHouse

CMS · Learning Management

2,301

Open-source LMS with AI tutoring, real-time collaboration boards, live code execution, and built-in course monetization — self-hosted in minutes.

View details
90
Repo Health
77
Technical
66
Dependency
Built with
Python 51%
TypeScript 48%
Updated 5 days ago
C++
66%
Other

Memgraph

AI Development · Databases

4,581

High-performance in-memory graph database for AI context and real-time analytics

View details
90
Repo Health
79
Technical
69
Dependency
Built with
C++ 66%
Python 18%
Updated 5 days ago
Python
100%
Other

OpenBB

Analytics · Databases · Invoicing Finance

73,553

The AI Workspace for Finance: Connect Data, Run AI Agents, Build Analytics

View details
77
Repo Health
80
Technical
67
Dependency
Built with
Python 100%
Updated 4 days ago

Join founders buildingwith open source

Opinionated takes, migration guides, cost-saving tips, and insights from the open source ecosystem.

Subscribe on Substack
Join 750+ subscribers