xml2rfc vulnerabilities
CVEs whose affected-version data names the xml2rfc package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2025-11059Highxml2rfc is vulnerable to arbitrary file reads through prepped files
xml2rfc is vulnerable to arbitrary file reads through prepped files
▾ Twilightxml2rfc · xml2rfcvia OSV
CVE-2025-11058Highxml2rfc has an arbitrary file read vulnerability
xml2rfc has an arbitrary file read vulnerability
▾ Twilightxml2rfc · xml2rfcvia OSV