VYPR
Moderate severityNVD Advisory· Published May 12, 2014· Updated May 6, 2026

CVE-2014-3243

CVE-2014-3243

Description

SOAPpy 0.12.5 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted SOAP request containing a large number of nested entity references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
SOAPpyPyPI
< 0.12.60.12.6

Affected products

1

Patches

2

Vulnerability mechanics

Generated on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

12

News mentions

0

No linked articles in our index yet.