security(quick-xml): bump version to 0.41.0

- and protect amount of properties
 - azure_core 0.21.0 is using quick-xml 0.31.0  which is Dos-able
   azure_core is no more maintained, would migrte to official azure lib
   later
This commit is contained in:
Edouard Vanbelle
2026-07-03 01:37:54 +02:00
parent dff0e7365e
commit 92d1a10d45
7 changed files with 78 additions and 11 deletions
@@ -243,7 +243,10 @@ fn collect_xml_text<R: std::io::BufRead>(
}
match xml.read_event_into(&mut buf) {
Ok(Event::Text(t)) => {
if let Ok(decoded) = t.xml_content() {
// quick-xml 0.41+ makes XmlVersion explicit on xml_content()
// so callers pick 1.0 vs 1.1 entity-normalization rules. Text
// extraction is version-agnostic — 1.0 is the sane default.
if let Ok(decoded) = t.xml_content(quick_xml::XmlVersion::Implicit1_0) {
out.push_str(&decoded);
}
}
@@ -203,7 +203,10 @@ impl WopiDiscoveryService {
for attr in e.attributes().flatten() {
let value = attr
.decode_and_unescape_value(reader.decoder())
.decoded_and_normalized_value(
quick_xml::XmlVersion::Implicit1_0,
reader.decoder(),
)
.map(|value| value.into_owned())
.unwrap_or_else(|_| String::from_utf8_lossy(&attr.value).to_string());