Universal Feed Parser (aka feedparser or python-feedparser) before 5.1.2 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML ENTITY declaration in a non-ASCII encoded document.
"https://github.com/pypa/advisory-database/blob/main/vulns/feedparser/PYSEC-2012-14.yaml"