{"id":"CVE-2022-37189","details":"DDMAL MEI2Volpiano 0.8.2 is vulnerable to XML External Entity (XXE), leading to a Denial of Service. This occurs due to the usage of the unsafe 'xml.etree' library to parse untrusted XML input.","aliases":["GHSA-6xm7-3cc5-47f9"],"modified":"2026-03-15T14:47:36.728957Z","published":"2022-09-07T13:15:09.380Z","references":[{"type":"ADVISORY","url":"https://docs.python.org/3/library/xml.html#xml-vulnerabilities"},{"type":"ADVISORY","url":"https://github.com/DDMAL/MEI2Volpiano/"},{"type":"ADVISORY","url":"https://pyup.io/vulnerabilities/CVE-2022-37189/50928/"},{"type":"FIX","url":"https://github.com/DDMAL/MEI2Volpiano/blob/987b70fff991235e682405f901388af0f414eaa8/mei2volpiano/mei2volpiano.py#L59"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ddmal/mei2volpiano","events":[{"introduced":"0"},{"last_affected":"987b70fff991235e682405f901388af0f414eaa8"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"0.8.2"}]}}],"versions":["0.0.1","0.1.0","0.2.0","0.5.0","0.6.0","0.6.1","0.7.0","0.7.1","0.7.2","0.7.3","0.8.0","0.8.1","0.8.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-37189.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}