Search/CVE-2013-1665
CVE

CVE-2013-1665

The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex and Folsom, Django, and possibly other products allow remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) attack.

CVSS v3.1
EPSS
4.63%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
EPSS Trend
Aug 16, 2026Sep 1, 2026
0.04pp
4.59% → 4.63% over 2 tracked changes
Connections
3 relationships
Timeline
disclosure → media coverage
Apr 3, 2013
Disclosure — published as a CVE record. · last revised by NVD Apr 29, 2026