models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XXE when parsing XMP metadata entries.
{ "binaries": [ { "binary_version": "1.10.3+dfsg-1", "binary_name": "python3-pikepdf" } ] }
{ "binaries": [ { "binary_version": "5.0.1+dfsg-1", "binary_name": "python3-pikepdf" } ] }
{ "binaries": [ { "binary_version": "8.7.1+dfsg-2build2", "binary_name": "python3-pikepdf" } ] }
{ "binaries": [ { "binary_version": "9.5.2+dfsg-1build2", "binary_name": "python3-pikepdf" } ] }