Brian Martin added the comment: Per http://expat.sourceforge.net/, version 2.1.1 fixes CVE-2015-1283, not 2.2.1 as mentioned in a comment. ---------- nosy: +Brian Martin _______________________________________ Python tracker <report at bugs.python.org> <http://bugs.python.org/issue26556> _______________________________________