CVE-2026-41066

EUVD-2026-25572
lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in the default configuration (with resolve_entities=True) allows untrusted XML input to read local files. Setting the resolve_entities option explicitly to resolve_entities='internal' or resolve_entities=False disables the local file access. This vulnerability is fixed in 6.1.0.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 18%
Affected Products (NVD)
VendorProductVersion
lxmllxml
𝑥
< 6.1.0
𝑥
= Vulnerable software versions
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
python-lxml
Amazon Linux 2
0:3.2.1-4.amzn2.0.8
fixed
python-lxml-debuginfo
Amazon Linux 2
0:3.2.1-4.amzn2.0.8
fixed
python-lxml-debugsource
Amazon Linux 2023
0:4.7.1-3.amzn2023.0.3
fixed
python-lxml-docs
Amazon Linux 2
0:3.2.1-4.amzn2.0.8
fixed
python3-lxml
Amazon Linux 2
0:3.2.1-4.amzn2.0.8
fixed
Amazon Linux 2023
0:4.7.1-3.amzn2023.0.3
fixed
python3-lxml-debuginfo
Amazon Linux 2023
0:4.7.1-3.amzn2023.0.3
fixed
python3.13-lxml
Amazon Linux 2023
0:5.3.2-3.amzn2023.0.2
fixed
python3.13-lxml-debuginfo
Amazon Linux 2023
0:5.3.2-3.amzn2023.0.2
fixed
python3.13-lxml-debugsource
Amazon Linux 2023
0:5.3.2-3.amzn2023.0.2
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
python-lxml
Azure Linux 3.0
0:4.9.3-2.azl3
fixed