Team Ai
Apppublic

parthtamu/rag-code-assistant

sourceHugging Faceupdated 7mo agoView on Hugging Face
0likes
xml.html438 linesDownload Raw Back to docs
1<!DOCTYPE html>2 3<html lang="en" data-content_root="../">4  <head>5    <meta charset="utf-8" />6    <meta name="viewport" content="width=device-width, initial-scale=1.0" /><meta name="viewport" content="width=device-width, initial-scale=1" />7<meta property="og:title" content="XML Processing Modules" />8<meta property="og:type" content="website" />9<meta property="og:url" content="https://docs.python.org/3/library/xml.html" />10<meta property="og:site_name" content="Python documentation" />11<meta property="og:description" content="Source code: Lib/xml/ Python’s interfaces for processing XML are grouped in the xml package. It is important to note that modules in the xml package require that there be at least one SAX-compliant..." />12<meta property="og:image:width" content="1146" />13<meta property="og:image:height" content="600" />14<meta property="og:image" content="https://docs.python.org/3.15/_images/social_previews/summary_library_xml_01fad792.png" />15<meta property="og:image:alt" content="Source code: Lib/xml/ Python’s interfaces for processing XML are grouped in the xml package. It is important to note that modules in the xml package require that there be at least one SAX-compliant..." />16<meta name="description" content="Source code: Lib/xml/ Python’s interfaces for processing XML are grouped in the xml package. It is important to note that modules in the xml package require that there be at least one SAX-compliant..." />17<meta name="twitter:card" content="summary_large_image" />18<meta name="theme-color" content="#3776ab">19 20    <title>XML Processing Modules &#8212; Python 3.15.0a6 documentation</title><meta name="viewport" content="width=device-width, initial-scale=1.0">21    22    <link rel="stylesheet" type="text/css" href="../_static/pygments.css?v=b86133f3" />23    <link rel="stylesheet" type="text/css" href="../_static/classic.css?v=234b1a7c" />24    <link rel="stylesheet" type="text/css" href="../_static/pydoctheme.css?v=89a2f22a" />25    <link rel="stylesheet" type="text/css" href="../_static/profiling-sampling-visualization.css?v=0c2600ae" />26    <link id="pygments_dark_css" media="(prefers-color-scheme: dark)" rel="stylesheet" type="text/css" href="../_static/pygments_dark.css?v=5349f25f" />27    28    <script src="../_static/documentation_options.js?v=6b7c9ff5"></script>29    <script src="../_static/doctools.js?v=9bcbadda"></script>30    <script src="../_static/sphinx_highlight.js?v=dc90522c"></script>31    <script src="../_static/profiling-sampling-visualization.js?v=9811ed04"></script>32    33    <script src="../_static/sidebar.js"></script>34    35    <link rel="search" type="application/opensearchdescription+xml"36          title="Search within Python 3.15.0a6 documentation"37          href="../_static/opensearch.xml"/>38    <link rel="author" title="About these documents" href="../about.html" />39    <link rel="index" title="Index" href="../genindex.html" />40    <link rel="search" title="Search" href="../search.html" />41    <link rel="copyright" title="Copyright" href="../copyright.html" />42    <link rel="next" title="xml.etree.ElementTree — The ElementTree XML API" href="xml.etree.elementtree.html" />43    <link rel="prev" title="html.entities — Definitions of HTML general entities" href="html.entities.html" />44    45      46      <script defer file-types="bz2,epub,zip" data-domain="docs.python.org" src="https://analytics.python.org/js/script.file-downloads.outbound-links.js"></script>47      48      <link rel="canonical" href="https://docs.python.org/3/library/xml.html">49      50    51 52    53    <style>54      @media only screen {55        table.full-width-table {56            width: 100%;57        }58      }59    </style>60<link rel="stylesheet" href="../_static/pydoctheme_dark.css" media="(prefers-color-scheme: dark)" id="pydoctheme_dark_css">61    <link rel="shortcut icon" type="image/png" href="../_static/py.svg">62            <script type="text/javascript" src="../_static/copybutton.js"></script>63            <script type="text/javascript" src="../_static/menu.js"></script>64            <script type="text/javascript" src="../_static/search-focus.js"></script>65            <script type="text/javascript" src="../_static/themetoggle.js"></script> 66            <script type="text/javascript" src="../_static/rtd_switcher.js"></script>67            <meta name="readthedocs-addons-api-version" content="1">68 69  </head>70<body>71<div class="mobile-nav">72    <input type="checkbox" id="menuToggler" class="toggler__input" aria-controls="navigation"73           aria-pressed="false" aria-expanded="false" role="button" aria-label="Menu">74    <nav class="nav-content" role="navigation">75        <label for="menuToggler" class="toggler__label">76            <span></span>77        </label>78        <span class="nav-items-wrapper">79            <a href="https://www.python.org/" class="nav-logo">80                <img src="../_static/py.svg" alt="Python logo">81            </a>82            <span class="version_switcher_placeholder"></span>83            <form role="search" class="search" action="../search.html" method="get">84                <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" class="search-icon">85                    <path fill-rule="nonzero" fill="currentColor" d="M15.5 14h-.79l-.28-.27a6.5 6.5 0 001.48-5.34c-.47-2.78-2.79-5-5.59-5.34a6.505 6.505 0 00-7.27 7.27c.34 2.8 2.56 5.12 5.34 5.59a6.5 6.5 0 005.34-1.48l.27.28v.79l4.25 4.25c.41.41 1.08.41 1.49 0 .41-.41.41-1.08 0-1.49L15.5 14zm-6 0C7.01 14 5 11.99 5 9.5S7.01 5 9.5 5 14 7.01 14 9.5 11.99 14 9.5 14z"></path>86                </svg>87                <input placeholder="Quick search" aria-label="Quick search" type="search" name="q">88                <input type="submit" value="Go">89            </form>90        </span>91    </nav>92    <div class="menu-wrapper">93        <nav class="menu" role="navigation" aria-label="main navigation">94            <div class="language_switcher_placeholder"></div>95            96<label class="theme-selector-label">97    Theme98    <select class="theme-selector" oninput="activateTheme(this.value)">99        <option value="auto" selected>Auto</option>100        <option value="light">Light</option>101        <option value="dark">Dark</option>102    </select>103</label>104  <div>105    <h3><a href="../contents.html">Table of Contents</a></h3>106    <ul>107<li><a class="reference internal" href="#">XML Processing Modules</a><ul>108<li><a class="reference internal" href="#xml-vulnerabilities">XML security</a></li>109</ul>110</li>111</ul>112 113  </div>114  <div>115    <h4>Previous topic</h4>116    <p class="topless"><a href="html.entities.html"117                          title="previous chapter"><code class="xref py py-mod docutils literal notranslate"><span class="pre">html.entities</span></code> — Definitions of HTML general entities</a></p>118  </div>119  <div>120    <h4>Next topic</h4>121    <p class="topless"><a href="xml.etree.elementtree.html"122                          title="next chapter"><code class="xref py py-mod docutils literal notranslate"><span class="pre">xml.etree.ElementTree</span></code> — The ElementTree XML API</a></p>123  </div>124  <script>125    document.addEventListener('DOMContentLoaded', () => {126        const title = document.querySelector('meta[property="og:title"]').content;127        const elements = document.querySelectorAll('.improvepage');128        const pageurl = window.location.href.split('?')[0];129        elements.forEach(element => {130            const url = new URL(element.href.split('?')[0].replace("-nojs", ""));131            url.searchParams.set('pagetitle', title);132            url.searchParams.set('pageurl', pageurl);133            url.searchParams.set('pagesource', "library/xml.rst");134            element.href = url.toString();135        });136    });137  </script>138  <div role="note" aria-label="source link">139    <h3>This page</h3>140    <ul class="this-page-menu">141      <li><a href="../bugs.html">Report a bug</a></li>142      <li><a class="improvepage" href="../improve-page-nojs.html">Improve this page</a></li>143      <li>144        <a href="https://github.com/python/cpython/blob/main/Doc/library/xml.rst?plain=1"145            rel="nofollow">Show source146        </a>147      </li>148      149    </ul>150  </div>151        </nav>152    </div>153</div>154 155  156    <div class="related" role="navigation" aria-label="Related">157      <h3>Navigation</h3>158      <ul>159        <li class="right" style="margin-right: 10px">160          <a href="../genindex.html" title="General Index"161             accesskey="I">index</a></li>162        <li class="right" >163          <a href="../py-modindex.html" title="Python Module Index"164             >modules</a> |</li>165        <li class="right" >166          <a href="xml.etree.elementtree.html" title="xml.etree.ElementTree — The ElementTree XML API"167             accesskey="N">next</a> |</li>168        <li class="right" >169          <a href="html.entities.html" title="html.entities — Definitions of HTML general entities"170             accesskey="P">previous</a> |</li>171 172          <li><img src="../_static/py.svg" alt="Python logo" style="vertical-align: middle; margin-top: -1px"></li>173          <li><a href="https://www.python.org/">Python</a> &#187;</li>174          <li class="switchers">175            <div class="language_switcher_placeholder"></div>176            <div class="version_switcher_placeholder"></div>177          </li>178          <li>179              180          </li>181    <li id="cpython-language-and-version">182      <a href="../index.html">3.15.0a6 Documentation</a> &#187;183    </li>184 185          <li class="nav-item nav-item-1"><a href="index.html" >The Python Standard Library</a> &#187;</li>186          <li class="nav-item nav-item-2"><a href="markup.html" accesskey="U">Structured Markup Processing Tools</a> &#187;</li>187        <li class="nav-item nav-item-this"><a href="">XML Processing Modules</a></li>188                <li class="right">189                    190 191    <div class="inline-search" role="search">192        <form class="inline-search" action="../search.html" method="get">193          <input placeholder="Quick search" aria-label="Quick search" type="search" name="q" id="search-box">194          <input type="submit" value="Go">195        </form>196    </div>197                     |198                </li>199            <li class="right">200<label class="theme-selector-label">201    Theme202    <select class="theme-selector" oninput="activateTheme(this.value)">203        <option value="auto" selected>Auto</option>204        <option value="light">Light</option>205        <option value="dark">Dark</option>206    </select>207</label> |</li>208            209      </ul>210    </div>    211 212    <div class="document">213      <div class="documentwrapper">214        <div class="bodywrapper">215          <div class="body" role="main">216            217  <section id="module-xml">218<span id="xml-processing-modules"></span><span id="xml"></span><h1>XML Processing Modules<a class="headerlink" href="#module-xml" title="Link to this heading">¶</a></h1>219<p><strong>Source code:</strong> <a class="extlink-source reference external" href="https://github.com/python/cpython/tree/main/Lib/xml/">Lib/xml/</a></p>220<hr class="docutils" />221<p>Python’s interfaces for processing XML are grouped in the <code class="docutils literal notranslate"><span class="pre">xml</span></code> package.</p>222<div class="admonition note">223<p class="admonition-title">Note</p>224<p>If you need to parse untrusted or unauthenticated data, see225<a class="reference internal" href="#xml-security"><span class="std std-ref">XML security</span></a>.</p>226</div>227<p>It is important to note that modules in the <code class="xref py py-mod docutils literal notranslate"><span class="pre">xml</span></code> package require that228there be at least one SAX-compliant XML parser available. The Expat parser is229included with Python, so the <a class="reference internal" href="pyexpat.html#module-xml.parsers.expat" title="xml.parsers.expat: An interface to the Expat non-validating XML parser."><code class="xref py py-mod docutils literal notranslate"><span class="pre">xml.parsers.expat</span></code></a> module will always be230available.</p>231<p>The documentation for the <a class="reference internal" href="xml.dom.html#module-xml.dom" title="xml.dom: Document Object Model API for Python."><code class="xref py py-mod docutils literal notranslate"><span class="pre">xml.dom</span></code></a> and <a class="reference internal" href="xml.sax.html#module-xml.sax" title="xml.sax: Package containing SAX2 base classes and convenience functions."><code class="xref py py-mod docutils literal notranslate"><span class="pre">xml.sax</span></code></a> packages are the232definition of the Python bindings for the DOM and SAX interfaces.</p>233<p>The XML handling submodules are:</p>234<ul class="simple">235<li><p><a class="reference internal" href="xml.etree.elementtree.html#module-xml.etree.ElementTree" title="xml.etree.ElementTree: Implementation of the ElementTree API."><code class="xref py py-mod docutils literal notranslate"><span class="pre">xml.etree.ElementTree</span></code></a>: the ElementTree API, a simple and lightweight236XML processor</p></li>237</ul>238<ul class="simple">239<li><p><a class="reference internal" href="xml.dom.html#module-xml.dom" title="xml.dom: Document Object Model API for Python."><code class="xref py py-mod docutils literal notranslate"><span class="pre">xml.dom</span></code></a>: the DOM API definition</p></li>240<li><p><a class="reference internal" href="xml.dom.minidom.html#module-xml.dom.minidom" title="xml.dom.minidom: Minimal Document Object Model (DOM) implementation."><code class="xref py py-mod docutils literal notranslate"><span class="pre">xml.dom.minidom</span></code></a>: a minimal DOM implementation</p></li>241<li><p><a class="reference internal" href="xml.dom.pulldom.html#module-xml.dom.pulldom" title="xml.dom.pulldom: Support for building partial DOM trees from SAX events."><code class="xref py py-mod docutils literal notranslate"><span class="pre">xml.dom.pulldom</span></code></a>: support for building partial DOM trees</p></li>242</ul>243<ul class="simple">244<li><p><a class="reference internal" href="xml.sax.html#module-xml.sax" title="xml.sax: Package containing SAX2 base classes and convenience functions."><code class="xref py py-mod docutils literal notranslate"><span class="pre">xml.sax</span></code></a>: SAX2 base classes and convenience functions</p></li>245<li><p><a class="reference internal" href="pyexpat.html#module-xml.parsers.expat" title="xml.parsers.expat: An interface to the Expat non-validating XML parser."><code class="xref py py-mod docutils literal notranslate"><span class="pre">xml.parsers.expat</span></code></a>: the Expat parser binding</p></li>246</ul>247<section id="xml-vulnerabilities">248<span id="xml-security"></span><span id="id1"></span><h2>XML security<a class="headerlink" href="#xml-vulnerabilities" title="Link to this heading">¶</a></h2>249<p>An attacker can abuse XML features to carry out denial of service attacks,250access local files, generate network connections to other machines, or251circumvent firewalls when attacker-controlled XML is being parsed,252in Python or elsewhere.</p>253<p>The built-in XML parsers of Python rely on the library <a class="reference external" href="https://github.com/libexpat/libexpat">libexpat</a>, commonly254called Expat, for parsing XML.</p>255<p>By default, Expat itself does not access local files or create network256connections.</p>257<p>Expat versions lower than 2.7.2 may be vulnerable to the “billion laughs”,258“quadratic blowup” and “large tokens” vulnerabilities, or to disproportional259use of dynamic memory.260Python bundles a copy of Expat, and whether Python uses the bundled or a261system-wide Expat, depends on how the Python interpreter262<a class="reference internal" href="../using/configure.html#cmdoption-with-system-expat"><code class="xref std std-option docutils literal notranslate"><span class="pre">has</span> <span class="pre">been</span> <span class="pre">configured</span></code></a> in your environment.263Python may be vulnerable if it uses such older versions of Expat.264Check <code class="xref py py-const docutils literal notranslate"><span class="pre">pyexpat.EXPAT_VERSION</span></code>.</p>265<p><a class="reference internal" href="xmlrpc.html#module-xmlrpc" title="xmlrpc: Server and client modules implementing XML-RPC."><code class="xref py py-mod docutils literal notranslate"><span class="pre">xmlrpc</span></code></a> is <strong>vulnerable</strong> to the “decompression bomb” attack.</p>266<dl class="simple">267<dt>billion laughs / exponential entity expansion</dt><dd><p>The <a class="reference external" href="https://en.wikipedia.org/wiki/Billion_laughs">Billion Laughs</a> attack – also known as exponential entity expansion –268uses multiple levels of nested entities. Each entity refers to another entity269several times, and the final entity definition contains a small string.270The exponential expansion results in several gigabytes of text and271consumes lots of memory and CPU time.</p>272</dd>273<dt>quadratic blowup entity expansion</dt><dd><p>A quadratic blowup attack is similar to a <a class="reference external" href="https://en.wikipedia.org/wiki/Billion_laughs">Billion Laughs</a> attack; it abuses274entity expansion, too. Instead of nested entities it repeats one large entity275with a couple of thousand chars over and over again. The attack isn’t as276efficient as the exponential case but it avoids triggering parser countermeasures277that forbid deeply nested entities.</p>278</dd>279<dt>decompression bomb</dt><dd><p>Decompression bombs (aka <a class="reference external" href="https://en.wikipedia.org/wiki/Zip_bomb">ZIP bomb</a>) apply to all XML libraries280that can parse compressed XML streams such as gzipped HTTP streams or281LZMA-compressed282files. For an attacker it can reduce the amount of transmitted data by three283magnitudes or more.</p>284</dd>285<dt>large tokens</dt><dd><p>Expat needs to re-parse unfinished tokens; without the protection286introduced in Expat 2.6.0, this can lead to quadratic runtime that can287be used to cause denial of service in the application parsing XML.288The issue is known as <span class="target" id="index-0"></span><a class="cve reference external" href="https://www.cve.org/CVERecord?id=CVE-2023-52425"><strong>CVE 2023-52425</strong></a>.</p>289</dd>290</dl>291</section>292</section>293 294 295            <div class="clearer"></div>296          </div>297        </div>298      </div>299      <div class="sphinxsidebar" role="navigation" aria-label="Main">300        <div class="sphinxsidebarwrapper">301  <div>302    <h3><a href="../contents.html">Table of Contents</a></h3>303    <ul>304<li><a class="reference internal" href="#">XML Processing Modules</a><ul>305<li><a class="reference internal" href="#xml-vulnerabilities">XML security</a></li>306</ul>307</li>308</ul>309 310  </div>311  <div>312    <h4>Previous topic</h4>313    <p class="topless"><a href="html.entities.html"314                          title="previous chapter"><code class="xref py py-mod docutils literal notranslate"><span class="pre">html.entities</span></code> — Definitions of HTML general entities</a></p>315  </div>316  <div>317    <h4>Next topic</h4>318    <p class="topless"><a href="xml.etree.elementtree.html"319                          title="next chapter"><code class="xref py py-mod docutils literal notranslate"><span class="pre">xml.etree.ElementTree</span></code> — The ElementTree XML API</a></p>320  </div>321  <script>322    document.addEventListener('DOMContentLoaded', () => {323        const title = document.querySelector('meta[property="og:title"]').content;324        const elements = document.querySelectorAll('.improvepage');325        const pageurl = window.location.href.split('?')[0];326        elements.forEach(element => {327            const url = new URL(element.href.split('?')[0].replace("-nojs", ""));328            url.searchParams.set('pagetitle', title);329            url.searchParams.set('pageurl', pageurl);330            url.searchParams.set('pagesource', "library/xml.rst");331            element.href = url.toString();332        });333    });334  </script>335  <div role="note" aria-label="source link">336    <h3>This page</h3>337    <ul class="this-page-menu">338      <li><a href="../bugs.html">Report a bug</a></li>339      <li><a class="improvepage" href="../improve-page-nojs.html">Improve this page</a></li>340      <li>341        <a href="https://github.com/python/cpython/blob/main/Doc/library/xml.rst?plain=1"342            rel="nofollow">Show source343        </a>344      </li>345      346    </ul>347  </div>348        </div>349<div id="sidebarbutton" title="Collapse sidebar">350<span>«</span>351</div>352 353      </div>354      <div class="clearer"></div>355    </div>  356    <div class="related" role="navigation" aria-label="Related">357      <h3>Navigation</h3>358      <ul>359        <li class="right" style="margin-right: 10px">360          <a href="../genindex.html" title="General Index"361             >index</a></li>362        <li class="right" >363          <a href="../py-modindex.html" title="Python Module Index"364             >modules</a> |</li>365        <li class="right" >366          <a href="xml.etree.elementtree.html" title="xml.etree.ElementTree — The ElementTree XML API"367             >next</a> |</li>368        <li class="right" >369          <a href="html.entities.html" title="html.entities — Definitions of HTML general entities"370             >previous</a> |</li>371 372          <li><img src="../_static/py.svg" alt="Python logo" style="vertical-align: middle; margin-top: -1px"></li>373          <li><a href="https://www.python.org/">Python</a> &#187;</li>374          <li class="switchers">375            <div class="language_switcher_placeholder"></div>376            <div class="version_switcher_placeholder"></div>377          </li>378          <li>379              380          </li>381    <li id="cpython-language-and-version">382      <a href="../index.html">3.15.0a6 Documentation</a> &#187;383    </li>384 385          <li class="nav-item nav-item-1"><a href="index.html" >The Python Standard Library</a> &#187;</li>386          <li class="nav-item nav-item-2"><a href="markup.html" >Structured Markup Processing Tools</a> &#187;</li>387        <li class="nav-item nav-item-this"><a href="">XML Processing Modules</a></li>388                <li class="right">389                    390 391    <div class="inline-search" role="search">392        <form class="inline-search" action="../search.html" method="get">393          <input placeholder="Quick search" aria-label="Quick search" type="search" name="q" id="search-box">394          <input type="submit" value="Go">395        </form>396    </div>397                     |398                </li>399            <li class="right">400<label class="theme-selector-label">401    Theme402    <select class="theme-selector" oninput="activateTheme(this.value)">403        <option value="auto" selected>Auto</option>404        <option value="light">Light</option>405        <option value="dark">Dark</option>406    </select>407</label> |</li>408            409      </ul>410    </div>  411    <div class="footer">412    &copy; <a href="../copyright.html">Copyright</a> 2001 Python Software Foundation.413    <br>414    This page is licensed under the Python Software Foundation License Version 2.415    <br>416    Examples, recipes, and other code in the documentation are additionally licensed under the Zero Clause BSD License.417    <br>418    419      See <a href="/license.html">History and License</a> for more information.<br>420    421    422    <br>423 424    The Python Software Foundation is a non-profit corporation.425<a href="https://www.python.org/psf/donations/">Please donate.</a>426<br>427    <br>428      Last updated on Mar 10, 2026 (08:58 UTC).429    430      <a href="/bugs.html">Found a bug</a>?431    432    <br>433 434    Created using <a href="https://www.sphinx-doc.org/">Sphinx</a> 8.2.3.435    </div>436 437  </body>438</html>