AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-27476

HIGH · CVSS 8.2 EPSS 0.98% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-03-08 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2023-27476
Severity
HIGH
CVSS
8.2
EPSS
0.98%

Original NVD Description

OWSLib is a Python package for client programming with Open Geospatial Consortium (OGC) web service interface standards, and their related content models. OWSLib's XML parser (which supports both `lxml` and `xml.etree`) does not disable entity resolution, and could lead to arbitrary file reads from an attacker-controlled XML payload. This affects all XML parsing in the codebase. This issue has been addressed in version 0.28.1. All users are advised to upgrade. The only known workaround is to patch the library manually. See `GHSA-8h9c-r582-mggc` for details.