Skip to main content
EPSS 0.3%top 74%

Papis: lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files (CVE-2026-41066)

0
High
Published: 08/13/2026 (08/13/2026, 17:25:32 UTC)
Source: GCVE Database
Product: papis

Description

### Impact Using either of the two parsers in the default configuration (with `resolve_entities=True`) allows untrusted XML input to read local files. ### Patches lxml 6.1.0 changes the default to `resolve_entities='internal'`, thus disallowing local file access by default. ### Workarounds Setting the `resolve_entities` option explicitly to `resolve_entities='internal'` or `resolve_entities=False` disables the local file access. ### Resources Original report: https://bugs.launchpad.net/lxml/+bug/2146291 The default option was changed to `resolve_entities='internal'` for the normal XML and HTML parsers in lxml 5.0. The default was not changed for `iterparse()` and `ETCompatXMLParser()` at the time. lxml 6.1 makes the safe option the default for all parsers.

CVSS v3.1

Score 7.5high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected software

lxml
pkg:pypi/lxml
Affected versions
=4.7.1
Homebrewmore threats →ghsa
papis
pkg:brew/papis
Affected versions
>=0.14.1 <0.15.0_3

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/17/2026, 03:26:06 UTC

Technical Analysis

CVE-2026-41066 is an information disclosure vulnerability in python-lxml where untrusted XML input can be exploited to read local files. This vulnerability was identified and fixed by the SUSE Product Security Team in their python-lxml packages. The affected versions include SUSE-specific builds such as python313-lxml-5.4.0-160000.3.1.aarch64 and python313-lxml-devel-5.4.0-160000.3.1.aarch64. No CVSS score is provided, and no known exploits in the wild have been reported.

Potential Impact

Successful exploitation of this vulnerability could allow an attacker to disclose local files on the affected system by supplying crafted XML input to python-lxml. This could lead to exposure of sensitive information stored locally.

Mitigation Recommendations

A security update has been released by the SUSE Product Security Team to fix this vulnerability. Users should apply the official update for python-lxml to remediate the issue. No additional mitigation steps are indicated.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
SUSE Product Security Team
Advisory Id
SUSE-SU-2026:2488-1
Cve Count
1

Threat ID: 6a3aab60eed863c81e3a58aa

Added to database: 06/23/2026, 15:50:56 UTC

Last enriched: 09/17/2026, 03:26:06 UTC

Last updated: 09/22/2026, 13:47:45 UTC

Views: 125

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses