PT-2026-34232 · Pypi+1 · Lxml+1

·

CVE-2026-41066

·

Published

2026-03-25

·

Updated

2026-08-19

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions lxml versions prior to 6.1.0
Description Using the default configuration with the resolve entities variable set to True allows untrusted XML input to read local files. This issue affects the iterparse() and ETCompatXMLParser() functions.
Recommendations Update to version 6.1.0. As a temporary workaround, explicitly set the resolve entities variable to internal or False to disable local file access.

Exploit

Fix

DoS

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-84038
BDU:2026-09700
CLEANSTART-2026-AN24336
CLEANSTART-2026-AZ09261
CLEANSTART-2026-CQ05396
CLEANSTART-2026-EM82280
CLEANSTART-2026-FU07345
CLEANSTART-2026-HP19968
CLEANSTART-2026-IR98353
CLEANSTART-2026-KE11953
CLEANSTART-2026-MR94452
CLEANSTART-2026-NL78203
CLEANSTART-2026-NM83456
CLEANSTART-2026-QE89118
CLEANSTART-2026-SO50412
CLEANSTART-2026-WQ85001
CLEANSTART-2026-WU03167
CVE-2026-41066
ECHO-E83F-9E30-4171
GHSA-VFMQ-68HX-4JFW
OESA-2026-2008
OESA-2026-2009
OESA-2026-2010
OESA-2026-2011
OESA-2026-2012
OPENSUSE-SU-2026:10596-1
OPENSUSE-SU-2026:20737-1
PYSEC-2026-87
SUSE-SU-2026:21587-1
SUSE-SU-2026:21603-1
SUSE-SU-2026:21731-1
SUSE-SU-2026:2488-1
SUSE-SU-2026:2728-1
SUSE-SU-2026:2729-1
SUSE-SU-2026:2752-1
SUSE-SU-2026:2754-1

Affected Products

Red Os
Lxml