The json2xml package through 3.12.0 for Python allows an error in typecode decoding enabling a remote attack that can lead to an exception, causing a denial of service.
"https://github.com/pypa/advisory-database/blob/main/vulns/json2xml/PYSEC-2023-149.yaml"