---
id: CVE-2014-3242
aliases:
  - GHSA-52wr-3vww-rmpq
  - PYSEC-2026-924
title: SOAPpy vulnerable to XML External Entity attacks
summary: SOAPpy vulnerable to XML External Entity attacks
severity: medium
vendor: soappy
product: soappy
ecosystem: pip
affected:
  - soappy <= 0.12.5
published: '2022-05-17'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-52wr-3vww-rmpq'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2014-3242'
  - url: 'https://github.com/kiorky/soappy'
  - url: 'https://web.archive.org/web/20150501220613/http://www.pnigos.com/?p=260'
  - url: >-
      https://web.archive.org/web/20200229062311/http://www.securityfocus.com/bid/67216
  - url: 'http://seclists.org/fulldisclosure/2014/May/20'
  - url: 'http://www.openwall.com/lists/oss-security/2014/05/06/1'
  - url: 'http://www.openwall.com/lists/oss-security/2014/05/06/9'
tags:
  - osv
  - pip
epss: 0.01812
epssPercentile: 0.77344
ingestedAt: '2026-07-08T18:25:45.743Z'
---

## Overview

SOAPpy 0.12.5 allows remote attackers to read arbitrary files via a SOAP request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

## Affected packages

- `soappy <= 0.12.5`

## Remediation

Refer to the advisory for the patched release.
