XML External Entity injection in Lxml - CVE-2026-41066
Published: April 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper restriction of xml external entity reference in iterparse() and ETCompatXMLParser() when parsing untrusted XML input. A remote attacker can send specially crafted XML input to disclose sensitive information.
The issue occurs when these parsers are used in the default configuration with resolve_entities=True.
Affected software
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
Python 3 Module
Basesystem Module
openSUSE Leap
Anolis OS
IBM Fusion HCI
Maximo Application Suite - Visual Inspection Component
Data Cataloging
InfoSphere Optim Archive Viewer
python3-lxml-debuginfo
python3-lxml
python3-lxml-debugsource
python-lxml-debugsource
python-lxml-debuginfo
python-lxml
python3-lxml-devel
python3-lxml-doc
python311-lxml-debuginfo
python311-lxml
python311-lxml-devel
How to mitigate CVE-2026-41066
IBM Fusion HCI - update to 2.13.0
Maximo Application Suite - Visual Inspection Component - addressed in versions 9.0.20, 9.1.17
Data Cataloging - update to 2.5.3
python3-lxml-debuginfo - addressed in versions 3.6.1-3.9.1, 4.7.1-150200.3.15.1, 4.9.1-150500.3.7.1
python3-lxml - addressed in versions 3.6.1-3.9.1, 4.7.1-150200.3.15.1, 4.9.1-150500.3.7.1
python3-lxml-debugsource - addressed in versions 3.6.1-3.9.1, 4.9.1-150500.3.7.1
python-lxml-debugsource - addressed in versions 3.6.1-8.8.1, 4.7.1-150200.3.15.1, 4.9.3-150400.8.11.1
python-lxml-debuginfo - addressed in versions 3.6.1-8.8.1, 4.7.1-150200.3.15.1
python-lxml - update to 3.6.1-8.8.1
python3-lxml-devel - update to 4.9.1-150500.3.7.1
python3-lxml-doc - update to 4.9.1-150500.3.7.1
python311-lxml-debuginfo - update to 4.9.3-150400.8.11.1
python311-lxml - update to 4.9.3-150400.8.11.1
python311-lxml-devel - update to 4.9.3-150400.8.11.1
python3-lxml - update to 6.1.0-1
python3-lxml-doc - update to 6.1.0-1
InfoSphere Optim Archive Viewer - update to 11.7.0.14
External References
Related Security Bulletins
- XML External Entity injection in Lxml
- Anolis OS update for python-lxml
- IBM InfoSphere Optim Archive Viewer update for lxml
- IBM Maximo Application Suite - Visual Inspection Component update for lxml
- SUSE update for python-lxml
- SUSE update for python-lxml
- SUSE update for python-lxml
- SUSE update for python3-lxml
- SUSE update for python3-lxml
- IBM Fusion, IBM Fusion HCI, and IBM Fusion Data Cataloging update for lxml