id: PYSEC-2026-3392 published: "2026-07-09T16:49:45.054237Z" modified: "2026-07-13T16:07:21.473112Z" aliases: - CVE-2022-26662 - GHSA-pm3h-mm62-pwm8 summary: XML Entity Expansion in trytond and proteus details: An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, 6.x through 6.0.4, and 6.1.x and 6.2.x through 6.2.1. An unauthenticated user can send a crafted XML-RPC message to consume all the resources of the server. affected: - package: name: trytond ecosystem: PyPI purl: pkg:pypi/trytond ranges: - type: ECOSYSTEM events: - introduced: 5.0.0 - fixed: 5.0.46 - introduced: 6.0.0 - fixed: 6.0.16 - introduced: 6.1.0 - fixed: 6.2.6 versions: - 5.0.0 - 5.0.1 - 5.0.10 - 5.0.11 - 5.0.12 - 5.0.13 - 5.0.14 - 5.0.15 - 5.0.16 - 5.0.17 - 5.0.18 - 5.0.19 - 5.0.2 - 5.0.20 - 5.0.21 - 5.0.22 - 5.0.23 - 5.0.24 - 5.0.25 - 5.0.26 - 5.0.27 - 5.0.28 - 5.0.29 - 5.0.3 - 5.0.30 - 5.0.31 - 5.0.32 - 5.0.33 - 5.0.34 - 5.0.35 - 5.0.36 - 5.0.37 - 5.0.38 - 5.0.39 - 5.0.4 - 5.0.40 - 5.0.41 - 5.0.42 - 5.0.43 - 5.0.44 - 5.0.45 - 5.0.5 - 5.0.6 - 5.0.7 - 5.0.8 - 5.0.9 - 6.0.0 - 6.0.1 - 6.0.10 - 6.0.11 - 6.0.12 - 6.0.13 - 6.0.14 - 6.0.15 - 6.0.2 - 6.0.3 - 6.0.4 - 6.0.5 - 6.0.6 - 6.0.7 - 6.0.8 - 6.0.9 - 6.2.0 - 6.2.1 - 6.2.2 - 6.2.3 - 6.2.4 - 6.2.5 references: - type: ADVISORY url: https://nvd.nist.gov/vuln/detail/CVE-2022-26662 - type: WEB url: https://bugs.tryton.org/issue11244 - type: WEB url: https://discuss.tryton.org/t/security-release-for-issue11219-and-issue11244/5059 - type: PACKAGE url: https://hg.tryton.org/trytond - type: WEB url: https://lists.debian.org/debian-lts-announce/2022/03/msg00016.html - type: WEB url: https://lists.debian.org/debian-lts-announce/2022/03/msg00017.html - type: WEB url: https://www.debian.org/security/2022/dsa-5098 - type: WEB url: https://www.debian.org/security/2022/dsa-5099 - type: PACKAGE url: https://pypi.org/project/trytond - type: ADVISORY url: https://github.com/advisories/GHSA-pm3h-mm62-pwm8 severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H