Comment 1 for bug 1100282

Revision history for this message
Thierry Carrez (ttx) wrote : Re: DoS through XML entity expansion

Looks like we could pass an etree.XMLParser with resolve_entities=False to etree.fromstring. Thoughts ?