{"id":"CVE-2016-5851","aliases":["GHSA-34wj-p5jm-2p96","PYSEC-2016-21"],"url":"https://o3.security/vulnerability/CVE-2016-5851","summary":"Improper Restriction of XML External Entity Reference in python-docx","details":"python-docx before 0.8.6 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted document.","published":"2016-12-21T22:59:00.170Z","modified":"2026-07-08T12:44:12.683519Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"python-docx","fixedVersion":"0.8.6"}],"fix":{"url":"https://github.com/python-openxml/python-docx/commit/61b40b161b64173ab8e362aec1fd197948431beb","label":"python-openxml/python-docx@61b40b1"},"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6FFMOH7ZPOPQWNJGUZOS5LXX4MGNRXXT/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XU2WSYRNB7CLBBFCGSX34XHACTA2SWDZ/"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2016/06/28/8"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/91485"},{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2016/06/28/7"},{"type":"FIX","url":"https://github.com/python-openxml/python-docx/blob/v0.8.6/HISTORY.rst"},{"type":"FIX","url":"https://github.com/python-openxml/python-docx/commit/61b40b161b64173ab8e362aec1fd197948431beb"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-5851"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-34wj-p5jm-2p96"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/python-docx/PYSEC-2016-21.yaml"},{"type":"PACKAGE","url":"https://github.com/python-openxml/python-docx"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6FFMOH7ZPOPQWNJGUZOS5LXX4MGNRXXT"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XU2WSYRNB7CLBBFCGSX34XHACTA2SWDZ"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6FFMOH7ZPOPQWNJGUZOS5LXX4MGNRXXT"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XU2WSYRNB7CLBBFCGSX34XHACTA2SWDZ"},{"type":"WEB","url":"https://web.archive.org/web/20170214030949/http://www.securityfocus.com/bid/91485"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T12:44:12.683519Z"}}