models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XXE when parsing XMP metadata entries.
{ "binaries": [ { "binary_name": "python3-pikepdf", "binary_version": "1.10.3+dfsg-1" } ] }
{ "binaries": [ { "binary_name": "python3-pikepdf", "binary_version": "5.0.1+dfsg-1" } ] }
{ "binaries": [ { "binary_name": "python3-pikepdf", "binary_version": "8.7.1+dfsg-2build2" } ] }
{ "binaries": [ { "binary_name": "python3-pikepdf", "binary_version": "9.5.2+dfsg-1build2" } ] }