CVE-2016-5851: Python-Openxml Project Python-Docx

High severity, CVSS 8.8. EPSS: 2.4% chance of exploitation in the next 30 days.

python-docx before 0.8.6 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted document.

Affected products

Published 2016-12-21. Last modified 2026-06-17.