8
I'm maintaining a production Django 1.5 application.
Recently there was a lot of noise about various vulnerabilities related to the loading of JSON, XML and YAML objects. If I understand correctly, input was carefully crafted to exploit bugs in the loading functions.
Now, I have no idea where Django (or the dozens of third-party apps that we use) use each of these protocols. How can I be safe from such vulnerabilities? Do I need to make sure in some way that Django is loading JSON, XML and YAML safely?