Papis: lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files (CVE-2026-41066)
### Impact Using either of the two parsers in the default configuration (with `resolve_entities=True`) allows untrusted XML input to read local files. ### Patches lxml 6.1.0 changes the default to `resolve_entities='internal'`, thus disallowing local file access by default. ### Workarounds Setting the `resolve_entities` option explicitly to `resolve_entities='internal'` or `resolve_entities=False` disables the local file access. ### Resources Original report: https://bugs.launchpad.net/lxml/+bug/2146291 The default option was changed to `resolve_entities='internal'` for the normal XML and HTML parsers in lxml 5.0. The default was not changed for `iterparse()` and `ETCompatXMLParser()` at the time. lxml 6.1 makes the safe option the default for all parsers.
AI Analysis
Technical Summary
CVE-2026-41066 is an information disclosure vulnerability in python-lxml where untrusted XML input can be exploited to read local files. This vulnerability was identified and fixed by the SUSE Product Security Team in their python-lxml packages. The affected versions include SUSE-specific builds such as python313-lxml-5.4.0-160000.3.1.aarch64 and python313-lxml-devel-5.4.0-160000.3.1.aarch64. No CVSS score is provided, and no known exploits in the wild have been reported.
Potential Impact
Successful exploitation of this vulnerability could allow an attacker to disclose local files on the affected system by supplying crafted XML input to python-lxml. This could lead to exposure of sensitive information stored locally.
Mitigation Recommendations
A security update has been released by the SUSE Product Security Team to fix this vulnerability. Users should apply the official update for python-lxml to remediate the issue. No additional mitigation steps are indicated.
Papis: lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files (CVE-2026-41066)
Description
### Impact Using either of the two parsers in the default configuration (with `resolve_entities=True`) allows untrusted XML input to read local files. ### Patches lxml 6.1.0 changes the default to `resolve_entities='internal'`, thus disallowing local file access by default. ### Workarounds Setting the `resolve_entities` option explicitly to `resolve_entities='internal'` or `resolve_entities=False` disables the local file access. ### Resources Original report: https://bugs.launchpad.net/lxml/+bug/2146291 The default option was changed to `resolve_entities='internal'` for the normal XML and HTML parsers in lxml 5.0. The default was not changed for `iterparse()` and `ETCompatXMLParser()` at the time. lxml 6.1 makes the safe option the default for all parsers.
CVSS v3.1
Score 7.5high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-41066 is an information disclosure vulnerability in python-lxml where untrusted XML input can be exploited to read local files. This vulnerability was identified and fixed by the SUSE Product Security Team in their python-lxml packages. The affected versions include SUSE-specific builds such as python313-lxml-5.4.0-160000.3.1.aarch64 and python313-lxml-devel-5.4.0-160000.3.1.aarch64. No CVSS score is provided, and no known exploits in the wild have been reported.
Potential Impact
Successful exploitation of this vulnerability could allow an attacker to disclose local files on the affected system by supplying crafted XML input to python-lxml. This could lead to exposure of sensitive information stored locally.
Mitigation Recommendations
A security update has been released by the SUSE Product Security Team to fix this vulnerability. Users should apply the official update for python-lxml to remediate the issue. No additional mitigation steps are indicated.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- SUSE Product Security Team
- Advisory Id
- SUSE-SU-2026:2488-1
- Cve Count
- 1
Threat ID: 6a3aab60eed863c81e3a58aa
Added to database: 06/23/2026, 15:50:56 UTC
Last enriched: 09/17/2026, 03:26:06 UTC
Last updated: 09/22/2026, 13:47:45 UTC
Views: 125
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.