models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XXE when parsing XMP metadata entries.
| Software | From | Fixed in |
|---|---|---|
| pikepdf_project / pikepdf | 1.3.0 | 2.9.2.x |
| fedoraproject / fedora | 32 | 32.x |
| fedoraproject / fedora | 33 | 33.x |
pikepdf
|
1.2.0 | 2.10.0 |