parthtamu/rag-code-assistant
0
1<!DOCTYPE html>2 3<html lang="en" data-content_root="../">4 <head>5 <meta charset="utf-8" />6 <meta name="viewport" content="width=device-width, initial-scale=1.0" /><meta name="viewport" content="width=device-width, initial-scale=1" />7<meta property="og:title" content="XML Processing Modules" />8<meta property="og:type" content="website" />9<meta property="og:url" content="https://docs.python.org/3/library/xml.html" />10<meta property="og:site_name" content="Python documentation" />11<meta property="og:description" content="Source code: Lib/xml/ Python’s interfaces for processing XML are grouped in the xml package. It is important to note that modules in the xml package require that there be at least one SAX-compliant..." />12<meta property="og:image:width" content="1146" />13<meta property="og:image:height" content="600" />14<meta property="og:image" content="https://docs.python.org/3.15/_images/social_previews/summary_library_xml_01fad792.png" />15<meta property="og:image:alt" content="Source code: Lib/xml/ Python’s interfaces for processing XML are grouped in the xml package. It is important to note that modules in the xml package require that there be at least one SAX-compliant..." />16<meta name="description" content="Source code: Lib/xml/ Python’s interfaces for processing XML are grouped in the xml package. It is important to note that modules in the xml package require that there be at least one SAX-compliant..." />17<meta name="twitter:card" content="summary_large_image" />18<meta name="theme-color" content="#3776ab">19 20 <title>XML Processing Modules — Python 3.15.0a6 documentation</title><meta name="viewport" content="width=device-width, initial-scale=1.0">21 22 <link rel="stylesheet" type="text/css" href="../_static/pygments.css?v=b86133f3" />23 <link rel="stylesheet" type="text/css" href="../_static/classic.css?v=234b1a7c" />24 <link rel="stylesheet" type="text/css" href="../_static/pydoctheme.css?v=89a2f22a" />25 <link rel="stylesheet" type="text/css" href="../_static/profiling-sampling-visualization.css?v=0c2600ae" />26 <link id="pygments_dark_css" media="(prefers-color-scheme: dark)" rel="stylesheet" type="text/css" href="../_static/pygments_dark.css?v=5349f25f" />27 28 <script src="../_static/documentation_options.js?v=6b7c9ff5"></script>29 <script src="../_static/doctools.js?v=9bcbadda"></script>30 <script src="../_static/sphinx_highlight.js?v=dc90522c"></script>31 <script src="../_static/profiling-sampling-visualization.js?v=9811ed04"></script>32 33 <script src="../_static/sidebar.js"></script>34 35 <link rel="search" type="application/opensearchdescription+xml"36 title="Search within Python 3.15.0a6 documentation"37 href="../_static/opensearch.xml"/>38 <link rel="author" title="About these documents" href="../about.html" />39 <link rel="index" title="Index" href="../genindex.html" />40 <link rel="search" title="Search" href="../search.html" />41 <link rel="copyright" title="Copyright" href="../copyright.html" />42 <link rel="next" title="xml.etree.ElementTree — The ElementTree XML API" href="xml.etree.elementtree.html" />43 <link rel="prev" title="html.entities — Definitions of HTML general entities" href="html.entities.html" />44 45 46 <script defer file-types="bz2,epub,zip" data-domain="docs.python.org" src="https://analytics.python.org/js/script.file-downloads.outbound-links.js"></script>47 48 <link rel="canonical" href="https://docs.python.org/3/library/xml.html">49 50 51 52 53 <style>54 @media only screen {55 table.full-width-table {56 width: 100%;57 }58 }59 </style>60<link rel="stylesheet" href="../_static/pydoctheme_dark.css" media="(prefers-color-scheme: dark)" id="pydoctheme_dark_css">61 <link rel="shortcut icon" type="image/png" href="../_static/py.svg">62 <script type="text/javascript" src="../_static/copybutton.js"></script>63 <script type="text/javascript" src="../_static/menu.js"></script>64 <script type="text/javascript" src="../_static/search-focus.js"></script>65 <script type="text/javascript" src="../_static/themetoggle.js"></script> 66 <script type="text/javascript" src="../_static/rtd_switcher.js"></script>67 <meta name="readthedocs-addons-api-version" content="1">68 69 </head>70<body>71<div class="mobile-nav">72 <input type="checkbox" id="menuToggler" class="toggler__input" aria-controls="navigation"73 aria-pressed="false" aria-expanded="false" role="button" aria-label="Menu">74 <nav class="nav-content" role="navigation">75 <label for="menuToggler" class="toggler__label">76 <span></span>77 </label>78 <span class="nav-items-wrapper">79 <a href="https://www.python.org/" class="nav-logo">80 <img src="../_static/py.svg" alt="Python logo">81 </a>82 <span class="version_switcher_placeholder"></span>83 <form role="search" class="search" action="../search.html" method="get">84 <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" class="search-icon">85 <path fill-rule="nonzero" fill="currentColor" d="M15.5 14h-.79l-.28-.27a6.5 6.5 0 001.48-5.34c-.47-2.78-2.79-5-5.59-5.34a6.505 6.505 0 00-7.27 7.27c.34 2.8 2.56 5.12 5.34 5.59a6.5 6.5 0 005.34-1.48l.27.28v.79l4.25 4.25c.41.41 1.08.41 1.49 0 .41-.41.41-1.08 0-1.49L15.5 14zm-6 0C7.01 14 5 11.99 5 9.5S7.01 5 9.5 5 14 7.01 14 9.5 11.99 14 9.5 14z"></path>86 </svg>87 <input placeholder="Quick search" aria-label="Quick search" type="search" name="q">88 <input type="submit" value="Go">89 </form>90 </span>91 </nav>92 <div class="menu-wrapper">93 <nav class="menu" role="navigation" aria-label="main navigation">94 <div class="language_switcher_placeholder"></div>95 96<label class="theme-selector-label">97 Theme98 <select class="theme-selector" oninput="activateTheme(this.value)">99 <option value="auto" selected>Auto</option>100 <option value="light">Light</option>101 <option value="dark">Dark</option>102 </select>103</label>104 <div>105 <h3><a href="../contents.html">Table of Contents</a></h3>106 <ul>107<li><a class="reference internal" href="#">XML Processing Modules</a><ul>108<li><a class="reference internal" href="#xml-vulnerabilities">XML security</a></li>109</ul>110</li>111</ul>112 113 </div>114 <div>115 <h4>Previous topic</h4>116 <p class="topless"><a href="html.entities.html"117 title="previous chapter"><code class="xref py py-mod docutils literal notranslate"><span class="pre">html.entities</span></code> — Definitions of HTML general entities</a></p>118 </div>119 <div>120 <h4>Next topic</h4>121 <p class="topless"><a href="xml.etree.elementtree.html"122 title="next chapter"><code class="xref py py-mod docutils literal notranslate"><span class="pre">xml.etree.ElementTree</span></code> — The ElementTree XML API</a></p>123 </div>124 <script>125 document.addEventListener('DOMContentLoaded', () => {126 const title = document.querySelector('meta[property="og:title"]').content;127 const elements = document.querySelectorAll('.improvepage');128 const pageurl = window.location.href.split('?')[0];129 elements.forEach(element => {130 const url = new URL(element.href.split('?')[0].replace("-nojs", ""));131 url.searchParams.set('pagetitle', title);132 url.searchParams.set('pageurl', pageurl);133 url.searchParams.set('pagesource', "library/xml.rst");134 element.href = url.toString();135 });136 });137 </script>138 <div role="note" aria-label="source link">139 <h3>This page</h3>140 <ul class="this-page-menu">141 <li><a href="../bugs.html">Report a bug</a></li>142 <li><a class="improvepage" href="../improve-page-nojs.html">Improve this page</a></li>143 <li>144 <a href="https://github.com/python/cpython/blob/main/Doc/library/xml.rst?plain=1"145 rel="nofollow">Show source146 </a>147 </li>148 149 </ul>150 </div>151 </nav>152 </div>153</div>154 155 156 <div class="related" role="navigation" aria-label="Related">157 <h3>Navigation</h3>158 <ul>159 <li class="right" style="margin-right: 10px">160 <a href="../genindex.html" title="General Index"161 accesskey="I">index</a></li>162 <li class="right" >163 <a href="../py-modindex.html" title="Python Module Index"164 >modules</a> |</li>165 <li class="right" >166 <a href="xml.etree.elementtree.html" title="xml.etree.ElementTree — The ElementTree XML API"167 accesskey="N">next</a> |</li>168 <li class="right" >169 <a href="html.entities.html" title="html.entities — Definitions of HTML general entities"170 accesskey="P">previous</a> |</li>171 172 <li><img src="../_static/py.svg" alt="Python logo" style="vertical-align: middle; margin-top: -1px"></li>173 <li><a href="https://www.python.org/">Python</a> »</li>174 <li class="switchers">175 <div class="language_switcher_placeholder"></div>176 <div class="version_switcher_placeholder"></div>177 </li>178 <li>179 180 </li>181 <li id="cpython-language-and-version">182 <a href="../index.html">3.15.0a6 Documentation</a> »183 </li>184 185 <li class="nav-item nav-item-1"><a href="index.html" >The Python Standard Library</a> »</li>186 <li class="nav-item nav-item-2"><a href="markup.html" accesskey="U">Structured Markup Processing Tools</a> »</li>187 <li class="nav-item nav-item-this"><a href="">XML Processing Modules</a></li>188 <li class="right">189 190 191 <div class="inline-search" role="search">192 <form class="inline-search" action="../search.html" method="get">193 <input placeholder="Quick search" aria-label="Quick search" type="search" name="q" id="search-box">194 <input type="submit" value="Go">195 </form>196 </div>197 |198 </li>199 <li class="right">200<label class="theme-selector-label">201 Theme202 <select class="theme-selector" oninput="activateTheme(this.value)">203 <option value="auto" selected>Auto</option>204 <option value="light">Light</option>205 <option value="dark">Dark</option>206 </select>207</label> |</li>208 209 </ul>210 </div> 211 212 <div class="document">213 <div class="documentwrapper">214 <div class="bodywrapper">215 <div class="body" role="main">216 217 <section id="module-xml">218<span id="xml-processing-modules"></span><span id="xml"></span><h1>XML Processing Modules<a class="headerlink" href="#module-xml" title="Link to this heading">¶</a></h1>219<p><strong>Source code:</strong> <a class="extlink-source reference external" href="https://github.com/python/cpython/tree/main/Lib/xml/">Lib/xml/</a></p>220<hr class="docutils" />221<p>Python’s interfaces for processing XML are grouped in the <code class="docutils literal notranslate"><span class="pre">xml</span></code> package.</p>222<div class="admonition note">223<p class="admonition-title">Note</p>224<p>If you need to parse untrusted or unauthenticated data, see225<a class="reference internal" href="#xml-security"><span class="std std-ref">XML security</span></a>.</p>226</div>227<p>It is important to note that modules in the <code class="xref py py-mod docutils literal notranslate"><span class="pre">xml</span></code> package require that228there be at least one SAX-compliant XML parser available. The Expat parser is229included with Python, so the <a class="reference internal" href="pyexpat.html#module-xml.parsers.expat" title="xml.parsers.expat: An interface to the Expat non-validating XML parser."><code class="xref py py-mod docutils literal notranslate"><span class="pre">xml.parsers.expat</span></code></a> module will always be230available.</p>231<p>The documentation for the <a class="reference internal" href="xml.dom.html#module-xml.dom" title="xml.dom: Document Object Model API for Python."><code class="xref py py-mod docutils literal notranslate"><span class="pre">xml.dom</span></code></a> and <a class="reference internal" href="xml.sax.html#module-xml.sax" title="xml.sax: Package containing SAX2 base classes and convenience functions."><code class="xref py py-mod docutils literal notranslate"><span class="pre">xml.sax</span></code></a> packages are the232definition of the Python bindings for the DOM and SAX interfaces.</p>233<p>The XML handling submodules are:</p>234<ul class="simple">235<li><p><a class="reference internal" href="xml.etree.elementtree.html#module-xml.etree.ElementTree" title="xml.etree.ElementTree: Implementation of the ElementTree API."><code class="xref py py-mod docutils literal notranslate"><span class="pre">xml.etree.ElementTree</span></code></a>: the ElementTree API, a simple and lightweight236XML processor</p></li>237</ul>238<ul class="simple">239<li><p><a class="reference internal" href="xml.dom.html#module-xml.dom" title="xml.dom: Document Object Model API for Python."><code class="xref py py-mod docutils literal notranslate"><span class="pre">xml.dom</span></code></a>: the DOM API definition</p></li>240<li><p><a class="reference internal" href="xml.dom.minidom.html#module-xml.dom.minidom" title="xml.dom.minidom: Minimal Document Object Model (DOM) implementation."><code class="xref py py-mod docutils literal notranslate"><span class="pre">xml.dom.minidom</span></code></a>: a minimal DOM implementation</p></li>241<li><p><a class="reference internal" href="xml.dom.pulldom.html#module-xml.dom.pulldom" title="xml.dom.pulldom: Support for building partial DOM trees from SAX events."><code class="xref py py-mod docutils literal notranslate"><span class="pre">xml.dom.pulldom</span></code></a>: support for building partial DOM trees</p></li>242</ul>243<ul class="simple">244<li><p><a class="reference internal" href="xml.sax.html#module-xml.sax" title="xml.sax: Package containing SAX2 base classes and convenience functions."><code class="xref py py-mod docutils literal notranslate"><span class="pre">xml.sax</span></code></a>: SAX2 base classes and convenience functions</p></li>245<li><p><a class="reference internal" href="pyexpat.html#module-xml.parsers.expat" title="xml.parsers.expat: An interface to the Expat non-validating XML parser."><code class="xref py py-mod docutils literal notranslate"><span class="pre">xml.parsers.expat</span></code></a>: the Expat parser binding</p></li>246</ul>247<section id="xml-vulnerabilities">248<span id="xml-security"></span><span id="id1"></span><h2>XML security<a class="headerlink" href="#xml-vulnerabilities" title="Link to this heading">¶</a></h2>249<p>An attacker can abuse XML features to carry out denial of service attacks,250access local files, generate network connections to other machines, or251circumvent firewalls when attacker-controlled XML is being parsed,252in Python or elsewhere.</p>253<p>The built-in XML parsers of Python rely on the library <a class="reference external" href="https://github.com/libexpat/libexpat">libexpat</a>, commonly254called Expat, for parsing XML.</p>255<p>By default, Expat itself does not access local files or create network256connections.</p>257<p>Expat versions lower than 2.7.2 may be vulnerable to the “billion laughs”,258“quadratic blowup” and “large tokens” vulnerabilities, or to disproportional259use of dynamic memory.260Python bundles a copy of Expat, and whether Python uses the bundled or a261system-wide Expat, depends on how the Python interpreter262<a class="reference internal" href="../using/configure.html#cmdoption-with-system-expat"><code class="xref std std-option docutils literal notranslate"><span class="pre">has</span> <span class="pre">been</span> <span class="pre">configured</span></code></a> in your environment.263Python may be vulnerable if it uses such older versions of Expat.264Check <code class="xref py py-const docutils literal notranslate"><span class="pre">pyexpat.EXPAT_VERSION</span></code>.</p>265<p><a class="reference internal" href="xmlrpc.html#module-xmlrpc" title="xmlrpc: Server and client modules implementing XML-RPC."><code class="xref py py-mod docutils literal notranslate"><span class="pre">xmlrpc</span></code></a> is <strong>vulnerable</strong> to the “decompression bomb” attack.</p>266<dl class="simple">267<dt>billion laughs / exponential entity expansion</dt><dd><p>The <a class="reference external" href="https://en.wikipedia.org/wiki/Billion_laughs">Billion Laughs</a> attack – also known as exponential entity expansion –268uses multiple levels of nested entities. Each entity refers to another entity269several times, and the final entity definition contains a small string.270The exponential expansion results in several gigabytes of text and271consumes lots of memory and CPU time.</p>272</dd>273<dt>quadratic blowup entity expansion</dt><dd><p>A quadratic blowup attack is similar to a <a class="reference external" href="https://en.wikipedia.org/wiki/Billion_laughs">Billion Laughs</a> attack; it abuses274entity expansion, too. Instead of nested entities it repeats one large entity275with a couple of thousand chars over and over again. The attack isn’t as276efficient as the exponential case but it avoids triggering parser countermeasures277that forbid deeply nested entities.</p>278</dd>279<dt>decompression bomb</dt><dd><p>Decompression bombs (aka <a class="reference external" href="https://en.wikipedia.org/wiki/Zip_bomb">ZIP bomb</a>) apply to all XML libraries280that can parse compressed XML streams such as gzipped HTTP streams or281LZMA-compressed282files. For an attacker it can reduce the amount of transmitted data by three283magnitudes or more.</p>284</dd>285<dt>large tokens</dt><dd><p>Expat needs to re-parse unfinished tokens; without the protection286introduced in Expat 2.6.0, this can lead to quadratic runtime that can287be used to cause denial of service in the application parsing XML.288The issue is known as <span class="target" id="index-0"></span><a class="cve reference external" href="https://www.cve.org/CVERecord?id=CVE-2023-52425"><strong>CVE 2023-52425</strong></a>.</p>289</dd>290</dl>291</section>292</section>293 294 295 <div class="clearer"></div>296 </div>297 </div>298 </div>299 <div class="sphinxsidebar" role="navigation" aria-label="Main">300 <div class="sphinxsidebarwrapper">301 <div>302 <h3><a href="../contents.html">Table of Contents</a></h3>303 <ul>304<li><a class="reference internal" href="#">XML Processing Modules</a><ul>305<li><a class="reference internal" href="#xml-vulnerabilities">XML security</a></li>306</ul>307</li>308</ul>309 310 </div>311 <div>312 <h4>Previous topic</h4>313 <p class="topless"><a href="html.entities.html"314 title="previous chapter"><code class="xref py py-mod docutils literal notranslate"><span class="pre">html.entities</span></code> — Definitions of HTML general entities</a></p>315 </div>316 <div>317 <h4>Next topic</h4>318 <p class="topless"><a href="xml.etree.elementtree.html"319 title="next chapter"><code class="xref py py-mod docutils literal notranslate"><span class="pre">xml.etree.ElementTree</span></code> — The ElementTree XML API</a></p>320 </div>321 <script>322 document.addEventListener('DOMContentLoaded', () => {323 const title = document.querySelector('meta[property="og:title"]').content;324 const elements = document.querySelectorAll('.improvepage');325 const pageurl = window.location.href.split('?')[0];326 elements.forEach(element => {327 const url = new URL(element.href.split('?')[0].replace("-nojs", ""));328 url.searchParams.set('pagetitle', title);329 url.searchParams.set('pageurl', pageurl);330 url.searchParams.set('pagesource', "library/xml.rst");331 element.href = url.toString();332 });333 });334 </script>335 <div role="note" aria-label="source link">336 <h3>This page</h3>337 <ul class="this-page-menu">338 <li><a href="../bugs.html">Report a bug</a></li>339 <li><a class="improvepage" href="../improve-page-nojs.html">Improve this page</a></li>340 <li>341 <a href="https://github.com/python/cpython/blob/main/Doc/library/xml.rst?plain=1"342 rel="nofollow">Show source343 </a>344 </li>345 346 </ul>347 </div>348 </div>349<div id="sidebarbutton" title="Collapse sidebar">350<span>«</span>351</div>352 353 </div>354 <div class="clearer"></div>355 </div> 356 <div class="related" role="navigation" aria-label="Related">357 <h3>Navigation</h3>358 <ul>359 <li class="right" style="margin-right: 10px">360 <a href="../genindex.html" title="General Index"361 >index</a></li>362 <li class="right" >363 <a href="../py-modindex.html" title="Python Module Index"364 >modules</a> |</li>365 <li class="right" >366 <a href="xml.etree.elementtree.html" title="xml.etree.ElementTree — The ElementTree XML API"367 >next</a> |</li>368 <li class="right" >369 <a href="html.entities.html" title="html.entities — Definitions of HTML general entities"370 >previous</a> |</li>371 372 <li><img src="../_static/py.svg" alt="Python logo" style="vertical-align: middle; margin-top: -1px"></li>373 <li><a href="https://www.python.org/">Python</a> »</li>374 <li class="switchers">375 <div class="language_switcher_placeholder"></div>376 <div class="version_switcher_placeholder"></div>377 </li>378 <li>379 380 </li>381 <li id="cpython-language-and-version">382 <a href="../index.html">3.15.0a6 Documentation</a> »383 </li>384 385 <li class="nav-item nav-item-1"><a href="index.html" >The Python Standard Library</a> »</li>386 <li class="nav-item nav-item-2"><a href="markup.html" >Structured Markup Processing Tools</a> »</li>387 <li class="nav-item nav-item-this"><a href="">XML Processing Modules</a></li>388 <li class="right">389 390 391 <div class="inline-search" role="search">392 <form class="inline-search" action="../search.html" method="get">393 <input placeholder="Quick search" aria-label="Quick search" type="search" name="q" id="search-box">394 <input type="submit" value="Go">395 </form>396 </div>397 |398 </li>399 <li class="right">400<label class="theme-selector-label">401 Theme402 <select class="theme-selector" oninput="activateTheme(this.value)">403 <option value="auto" selected>Auto</option>404 <option value="light">Light</option>405 <option value="dark">Dark</option>406 </select>407</label> |</li>408 409 </ul>410 </div> 411 <div class="footer">412 © <a href="../copyright.html">Copyright</a> 2001 Python Software Foundation.413 <br>414 This page is licensed under the Python Software Foundation License Version 2.415 <br>416 Examples, recipes, and other code in the documentation are additionally licensed under the Zero Clause BSD License.417 <br>418 419 See <a href="/license.html">History and License</a> for more information.<br>420 421 422 <br>423 424 The Python Software Foundation is a non-profit corporation.425<a href="https://www.python.org/psf/donations/">Please donate.</a>426<br>427 <br>428 Last updated on Mar 10, 2026 (08:58 UTC).429 430 <a href="/bugs.html">Found a bug</a>?431 432 <br>433 434 Created using <a href="https://www.sphinx-doc.org/">Sphinx</a> 8.2.3.435 </div>436 437 </body>438</html>