> defusedxml.lxml is no longer needed and supported. Nowadays libxml2 has builtin limitation for entity expansion.
https://github.com/tiran/defusedxml/issues/25#issuecomment-4...
See https://lxml.de/FAQ.html#is-lxml-vulnerable-to-xml-bombs for more about the tuning knobs.
> defusedxml.lxml is no longer needed and supported. Nowadays libxml2 has builtin limitation for entity expansion.
https://github.com/tiran/defusedxml/issues/25#issuecomment-4...