Junglewise Threat Intelligence

GateNLP Ultimate Sitemap Parser DoS via XML Entity Expansion

Severity: high · CVSS 7.5 · Published 2026-06-19

Vendors: PyPI.

Executive brief

The Ultimate Sitemap Parser (USP) library is used by web crawlers and monitoring tools to read website sitemaps. A vulnerability allows an attacker to provide a specially crafted sitemap that causes the application to consume excessive CPU and memory, leading to a complete system hang or crash. This can be used to disable web indexers, automated CI/CD pipelines, or any service that processes external sitemaps.

Technical details

The vulnerability is a CWE-776 XML Entity Expansion (Billion Laughs) attack within the XMLSitemapParser component. The library uses Python's 'xml.parsers.expat' to parse sitemaps without disabling DTD declarations or restricting recursive entity references. An attacker can trigger exponential resource consumption by serving a malicious XML sitemap containing nested entities. The vulnerability is reachable via public API entry points 'sitemap_tree_for_homepage()' and 'sitemap_from_str()'. Version 1.8.1 resolves this issue by implementing proper XML parsing restrictions.

Affected products

  • GateNLP ultimate-sitemap-parser <= 1.8.0

Timeline

  • 2026-06-16: disclosed
  • 2026-06-19: advisory: Advisory updated and published on GitHub
  • 2026-06-19: patched: Version 1.8.1 released

References

Related threats