PT-2026-34232 · Pypi · Lxml
Brubbish
·
Published
2026-04-21
·
Updated
2026-04-29
·
CVE-2026-41066
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
lxml versions prior to 6.1.0
Description
Using the default configuration with the
resolve entities variable set to True allows untrusted XML input to read local files. This issue affects the iterparse() and ETCompatXMLParser() functions.Recommendations
Update to version 6.1.0.
As a temporary workaround, explicitly set the
resolve entities variable to internal or False to disable local file access.Exploit
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lxml