---
id: CVE-2022-26662
aliases:
  - GHSA-pm3h-mm62-pwm8
  - PYSEC-2022-43171
  - PYSEC-2026-741
title: XML Entity Expansion in trytond and proteus
summary: XML Entity Expansion in trytond and proteus
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
vendor: trytond
product: trytond
ecosystem: pip
affected:
  - 'trytond >= 5.0.0, < 5.0.46'
  - 'trytond >= 6.0.0, < 6.0.16'
  - 'trytond >= 6.1.0, < 6.2.6'
  - 'proteus >= 5.0.0, < 5.0.12'
  - 'proteus >= 6.0.0, < 6.0.5'
  - 'proteus >= 6.1.0, < 6.2.2'
patched:
  - trytond 5.0.46
  - trytond 6.0.16
  - trytond 6.2.6
  - proteus 5.0.12
  - proteus 6.0.5
  - proteus 6.2.2
published: '2022-03-11'
updated: '2026-07-06'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-pm3h-mm62-pwm8'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2022-26662'
  - url: 'https://bugs.tryton.org/issue11244'
  - url: >-
      https://discuss.tryton.org/t/security-release-for-issue11219-and-issue11244/5059
  - url: 'https://hg.tryton.org/trytond'
  - url: 'https://lists.debian.org/debian-lts-announce/2022/03/msg00016.html'
  - url: 'https://lists.debian.org/debian-lts-announce/2022/03/msg00017.html'
  - url: 'https://www.debian.org/security/2022/dsa-5098'
  - url: 'https://www.debian.org/security/2022/dsa-5099'
tags:
  - osv
  - pip
epss: 0.01973
epssPercentile: 0.79591
ingestedAt: '2026-07-08T18:25:51.791Z'
---

## Overview

An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, 6.x through 6.0.4, and 6.1.x and 6.2.x through 6.2.1. An unauthenticated user can send a crafted XML-RPC message to consume all the resources of the server.

## Affected packages

- `trytond >= 5.0.0, < 5.0.46`
- `trytond >= 6.0.0, < 6.0.16`
- `trytond >= 6.1.0, < 6.2.6`
- `proteus >= 5.0.0, < 5.0.12`
- `proteus >= 6.0.0, < 6.0.5`
- `proteus >= 6.1.0, < 6.2.2`

## Remediation

Upgrade to a patched release:

- `trytond 5.0.46`
- `trytond 6.0.16`
- `trytond 6.2.6`
- `proteus 5.0.12`
- `proteus 6.0.5`
- `proteus 6.2.2`
