{"id":"CVE-2021-39371","aliases":["GHSA-p9wf-3xpg-c9g5","PYSEC-2021-121"],"url":"https://o3.security/vulnerability/CVE-2021-39371","summary":"XML External Entity Injection in PyWPS","details":"An XML external entity (XXE) injection in PyWPS before 4.4.5 allows an attacker to view files on the application server filesystem by assigning a path to the entity. OWSLib 0.24.1 may also be affected.","published":"2021-08-23T01:15:06.373Z","modified":"2026-07-08T06:03:35.731854352Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":{"score":0.01524,"percentile":0.72296,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"pywps","fixedVersion":"4.5.0"}],"fix":{"url":"https://github.com/geopython/pywps/pull/616","label":"geopython/pywps#616"},"references":[{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2021/09/msg00001.html"},{"type":"FIX","url":"https://github.com/geopython/OWSLib/issues/790"},{"type":"FIX","url":"https://github.com/geopython/pywps/pull/616"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T06:03:35.731854352Z"}}