CVE-2026-41066

EUVD-2026-25572
lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in the default configuration (with resolve_entities=True) allows untrusted XML input to read local files. Setting the resolve_entities option explicitly to resolve_entities='internal' or resolve_entities=False disables the local file access. This vulnerability is fixed in 6.1.0.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 24%
Affected Products (NVD)
VendorProductVersion
lxmllxml
𝑥
< 6.1.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
lxml
bookworm
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
6.1.0-1
fixed
sid
6.1.0-1
fixed
trixie
no-dsa
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
python-lxml
suse enterprise server 12 SP3
3.6.1-8.8.1
fixed
python3-lxml
suse enterprise desktop 15 SP7
4.9.1-150500.3.7.1
fixed
suse enterprise sap 12
3.3.5-3.18.1
fixed
suse enterprise sap 12 SP3
3.3.5-3.18.1
fixed
suse enterprise sap 12 SP4
3.3.5-3.18.1
fixed
suse enterprise sap 12 SP5
3.3.5-3.18.1
fixed
suse enterprise sap 15 SP7
4.9.1-150500.3.7.1
fixed
suse enterprise server 12
3.3.5-3.18.1
fixed
suse enterprise server 12 SP3
3.3.5-3.18.1
fixed
suse enterprise server 12 SP4
3.3.5-3.18.1
fixed
suse enterprise server 12 SP5
3.3.5-3.18.1
fixed
suse enterprise server 15 SP4
4.7.1-150200.3.15.1
fixed
suse enterprise server 15 SP7
4.9.1-150500.3.7.1
fixed
python3-lxml-devel
suse enterprise desktop 15 SP7
4.9.1-150500.3.7.1
fixed
suse enterprise sap 15 SP7
4.9.1-150500.3.7.1
fixed
suse enterprise server 15 SP4
4.7.1-150200.3.15.1
fixed
suse enterprise server 15 SP7
4.9.1-150500.3.7.1
fixed
python3-lxml-doc
suse enterprise sap 12
3.3.5-3.18.1
fixed
suse enterprise sap 12 SP3
3.3.5-3.18.1
fixed
suse enterprise sap 12 SP4
3.3.5-3.18.1
fixed
suse enterprise sap 12 SP5
3.3.5-3.18.1
fixed
suse enterprise server 12
3.3.5-3.18.1
fixed
suse enterprise server 12 SP3
3.3.5-3.18.1
fixed
suse enterprise server 12 SP4
3.3.5-3.18.1
fixed
suse enterprise server 12 SP5
3.3.5-3.18.1
fixed
python311-lxml
suse enterprise server 15 SP4
4.9.3-150400.8.11.1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
python-lxml
Amazon Linux 2
0:3.2.1-4.amzn2.0.8
fixed
python-lxml-debuginfo
Amazon Linux 2
0:3.2.1-4.amzn2.0.8
fixed
python-lxml-debugsource
Amazon Linux 2023
0:4.7.1-3.amzn2023.0.3
fixed
python-lxml-docs
Amazon Linux 2
0:3.2.1-4.amzn2.0.8
fixed
python3-lxml
Amazon Linux 2
0:3.2.1-4.amzn2.0.8
fixed
Amazon Linux 2023
0:4.7.1-3.amzn2023.0.3
fixed
python3-lxml-debuginfo
Amazon Linux 2023
0:4.7.1-3.amzn2023.0.3
fixed
python3.13-lxml
Amazon Linux 2023
0:5.3.2-3.amzn2023.0.2
fixed
python3.13-lxml-debuginfo
Amazon Linux 2023
0:5.3.2-3.amzn2023.0.2
fixed
python3.13-lxml-debugsource
Amazon Linux 2023
0:5.3.2-3.amzn2023.0.2
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
python-lxml
Azure Linux 3.0
0:4.9.3-2.azl3
fixed