StackRadar

CVE-2026-41066

High

Advisory

Published 21 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
163
of 17,781 indexed, latest versions
Container images
164
deployed by those charts
Fix available
1 of 2
affected packages

lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files

Carried by container images the latest versions of 163 of 17,781 indexed charts deploy, on 164 images.

Affected packageAffected versionsFixed inImages
lxmlpypi3.2.1, 3.6.4, 4.1.0, 4.2.1+32 more6.1.0164
lxmldeb4.8.0-1build1, 5.2.1-1, 5.4.0-1no fix listed3
OSV records
DEBIAN-CVE-2026-41066GHSA-vfmq-68hx-4jfwUBUNTU-CVE-2026-41066
Also known as
PYSEC-2026-87

Charts affected

163 by stars
ChartLatestAffected imagesRadar Score
frigateimprowisedVerified publisher1.1.01 of 1See more

frigate improwised 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ghcr.io/blakeblackshear/frigate:0.13.07a5244e4c8dc
lxml@5.1.0
6.1.0

Open the chart page →

2,159
guardrails-usvcinfracloud-chartsVerified publisher1.0.11 of 1See more

guardrails-usvc infracloud-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/guardrails-tgi:latestf68bec6a1271
lxml@5.3.0
6.1.0

Open the chart page →

5,062
label-studioinseefrlab2.3.11 of 3See more

label-studio inseefrlab 2.3.1

1 of the 3 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
heartexlabs/label-studio:latestaa461572e8f9
lxml@5.3.0
6.1.0

Open the chart page →

3,157
intelowlintelowl-helm6.6.1-01-06-20261 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

1 of the 5 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
lxml@6.0.2
6.1.0

Open the chart page →

17,852
inventreeinventreeOfficialVerified publisher0.4.281 of 2See more

inventree inventree 0.4.28

1 of the 2 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
inventree/inventree:1.5.4a946ec09da3e
lxml@5.4.0-1
lxml@5.4.0
no fix listed
6.1.0

Open the chart page →

5,788
jx-app-datadogjenkins-x0.0.101 of 2See more

jx-app-datadog jenkins-x 0.0.10

1 of the 2 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
datadog/agent:6aad9994de6a7
lxml@4.9.2
6.1.0

Open the chart page →

3,999
dynamo-dbk8s-home-lab-repo0.0.31 of 1See more

dynamo-db k8s-home-lab-repo 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
amazon/dynamodb-local:1.20.01ed00881c937
lxml@3.2.1
6.1.0

Open the chart page →

444
paperlessk8s-home-lab-repo11.0.11 of 1See more

paperless k8s-home-lab-repo 11.0.1

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
lxml@6.0.2
6.1.0

Open the chart page →

9,103
authentikkagiso-me0.1.11 of 1See more

authentik kagiso-me 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
lxml@6.0.2
6.1.0

Open the chart page →

4,568
huekatool1.0.81 of 1See more

hue katool 1.0.8

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
gethue/hue:4.11.011b649636e68
lxml@4.9.1
6.1.0

Open the chart page →

16,417
home-assistantkfirfer0.5.41 of 1See more

home-assistant kfirfer 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.10.3021e2afc6e57
lxml@4.9.3
6.1.0

Open the chart page →

6,447
mindsdbkronkltdVerified publisher0.1.01 of 1See more

mindsdb kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
mindsdb/mindsdb:latest163011c09299
lxml@5.3.0
6.1.0

Open the chart page →

9,620
aperagkubeblocksVerified publisher0.0.0-nightly1 of 3See more

aperag kubeblocks 0.0.0-nightly

1 of the 3 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
lxml@5.3.2
6.1.0

Open the chart page →

8,405
nacoskubesphere-testVerified publisher0.1.11 of 1See more

nacos kubesphere-test 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
nacos/nacos-server:1.4.1fe6e5688cdf3
lxml@3.2.1
6.1.0

Open the chart page →

4,153
hyperglassm0nsterrr-hyperglassVerified publisher4.2.11 of 2See more

hyperglass m0nsterrr-hyperglass 4.2.1

1 of the 2 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
lxml@5.2.2
6.1.0

Open the chart page →

4,647
fossologymidokura-communityVerified publisher0.2.21 of 2See more

fossology midokura-community 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
fossology/fossology:4.2.18bd1f22ba7bb
lxml@4.9.1
6.1.0

Open the chart page →

3,294
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
lxml@4.9.1
6.1.0

Open the chart page →

43,341
paperless-ngxmt1905027.6.141 of 4See more

paperless-ngx mt190502 7.6.14

1 of the 4 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
lxml@6.0.2
6.1.0

Open the chart page →

11,950
polyglotncsaVerified publisher0.1.11 of 18See more

polyglot ncsa 0.1.1

1 of the 18 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
lxml@4.2.5
6.1.0

Open the chart page →

55,726
ponsimv2opencord1.2.31 of 2See more

ponsimv2 opencord 1.2.3

1 of the 2 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
voltha/voltha-tester:1.7.0655c3048a602
lxml@3.6.4
6.1.0

Open the chart page →

12,609
sebaopencord1.0.04 of 17See more

seba opencord 1.0.0

4 of the 17 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
voltha/voltha-cli:1.6.0c4e41e92f046
lxml@3.6.4
6.1.0
voltha/voltha-netconf:1.6.037f80524c207
lxml@3.6.4
6.1.0
voltha/voltha-ofagent:1.6.09ee8c1f4428c
lxml@3.6.4
6.1.0
voltha/voltha-voltha:1.6.0ff596b62de59
lxml@3.6.4
6.1.0

Open the chart page →

93,855
home-assistantpascaliskeVerified publisher0.1.11 of 1See more

home-assistant pascaliske 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
lxml@6.0.1
6.1.0

Open the chart page →

4,749
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
lxml@4.9.1
6.1.0

Open the chart page →

22,084
libretimepodzone-chartsVerified publisher0.4.11 of 9See more

libretime podzone-charts 0.4.1

1 of the 9 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ghcr.io/libretime/libretime-playout:latest71a8706531aa
lxml@5.4.0
6.1.0

Open the chart page →

11,149
powerdnspuckpuck2.0.01 of 4See more

powerdns puckpuck 2.0.0

1 of the 4 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
pschiffe/pdns-admin:0.4.137ebba8c2b8f
lxml@4.6.5
6.1.0

Open the chart page →

4,616
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
apache/airflow:2.10.2-python3.9ce90bdc3d2af
lxml@5.3.0
6.1.0

Open the chart page →

21,211
iparedhat-cop1.3.91 of 1See more

ipa redhat-cop 1.3.9

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
quay.io/freeipa/freeipa-server:fedora-39-4.11.1d422ee50c2c3
lxml@4.9.3
6.1.0

Open the chart page →

951
gristrlex0.1.01 of 1See more

grist rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
gristlabs/grist:0.7.96e71b1914a7e
lxml@4.6.3
6.1.0

Open the chart page →

5,215
matrix-stackrock8sVerified publisher0.8.11 of 7See more

matrix-stack rock8s 0.8.1

1 of the 7 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
lxml@5.3.0
6.1.0

Open the chart page →

9,256
checkmkrtomik-helm-chartsVerified publisher0.1.01 of 1See more

checkmk rtomik-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
checkmk/check-mk-community:2.5.0p6c11b422210c4
lxml@6.0.4
6.1.0

Open the chart page →

7,436
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
lxml@6.0.2
6.1.0

Open the chart page →

10,605
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
lxml@6.0.2
6.1.0

Open the chart page →

4,499
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
lxml@6.0.2
6.1.0

Open the chart page →

6,207
nacossaber0.1.111 of 1See more

nacos saber 0.1.11

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
nacos/nacos-server:v2.1.0dcf04549c6d7
lxml@3.2.1
6.1.0

Open the chart page →

3,978
airflowsb-helm-charts0.3.01 of 1See more

airflow sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
apache/airflow:2.8.1e5560ad0b86e
lxml@5.1.0
6.1.0

Open the chart page →

10,209
scapyscapy-containerised0.3.41 of 2See more

scapy scapy-containerised 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
saidsef/scapy-containerised:v2025.02f17f7c435891
lxml@5.3.1
6.1.0

Open the chart page →

2,817
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
lxml@4.3.2
6.1.0

Open the chart page →

8,694
mealiesmarthallVerified publisher0.0.101 of 1See more

mealie smarthall 0.0.10

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
lxml@5.1.0
6.1.0

Open the chart page →

5,565
srebotsrebot0.14.01 of 2See more

srebot srebot 0.14.0

1 of the 2 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ghcr.io/shadrus/srebot:0.14.09b4415e937b2
lxml@6.0.3
6.1.0

Open the chart page →

1,542
datapusherstatcan1.0.01 of 1See more

datapusher statcan 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
keitaro/ckan-datapusher:0.0.175bf1a45f45c1
lxml@4.5.2
6.1.0

Open the chart page →

3,044
icinga2svtech-public-helm-charts1.0.01 of 4See more

icinga2 svtech-public-helm-charts 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
svtechnmaa/svtech_icinga2:v1.1.667be2aba9436
lxml@5.1.0
6.1.0

Open the chart page →

5,511
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
lxml@4.9.0
6.1.0

Open the chart page →

18,756
stashswuuper-githubVerified publisher0.1.161 of 1See more

stash swuuper-github 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
stashapp/stash:v0.31.1df744af5a0c9
lxml@6.0.2
6.1.0

Open the chart page →

2,396
hadoop-deploymenttejaswita-hadoop-helmchart1.0.01 of 1See more

hadoop-deployment tejaswita-hadoop-helmchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
apache/hadoop:3af361b20bec0
lxml@3.2.1
6.1.0

Open the chart page →

4,240
asrtest-opea1.0.01 of 1See more

asr test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/asr:1.025dd26d9cd09
lxml@5.3.0
6.1.0

Open the chart page →

4,393
chatqnatest-opea1.0.04 of 11See more

chatqna test-opea 1.0.0

4 of the 11 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/embedding-tei:1.05c9639de61c1
lxml@5.3.0
6.1.0
opea/llm-tgi:1.00c25aab3f106
lxml@5.3.0
6.1.0
opea/reranking-tei:1.0e48613afb191
lxml@5.3.0
6.1.0
opea/retriever-redis:1.0eb746b263705
lxml@5.3.0
6.1.0

Open the chart page →

39,090
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/llm-tgi:1.00c25aab3f106
lxml@5.3.0
6.1.0

Open the chart page →

28,814
codetranstest-opea1.0.01 of 5See more

codetrans test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/llm-tgi:1.00c25aab3f106
lxml@5.3.0
6.1.0

Open the chart page →

28,385
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/llm-docsum-tgi:1.002f9e8fa5d71
lxml@5.3.0
6.1.0

Open the chart page →

28,858
embedding-usvctest-opea1.0.01 of 1See more

embedding-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/embedding-tei:1.05c9639de61c1
lxml@5.3.0
6.1.0

Open the chart page →

5,185

Container images carrying it

164 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
hkotel/mealie:api-v1.0.0beta-2a7e6b6abe087
lxml@4.8.0
6.1.0
1
homeassistant/home-assistant:2023.10.3021e2afc6e57
lxml@4.9.3
6.1.0
1
homeassistant/home-assistant:2023.12.48d000332b09b
lxml@4.9.3
6.1.0
1
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
lxml@3.2.1
6.1.0
1
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
lxml@3.2.1
6.1.0
1
ibmcom/bai-flink-zookeeper-dev:19.0.258548034cf55
lxml@3.2.1
6.1.0
1
improwised/erpnext-worker:v13.4.197280b55cbd4
lxml@4.6.3
6.1.0
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
lxml@6.0.2
6.1.0
1
inventree/inventree:1.5.4a946ec09da3e
lxml@5.4.0-1
lxml@5.4.0
no fix listed
6.1.0
1
keitaro/ckan-datapusher:0.0.175bf1a45f45c1
lxml@4.5.2
6.1.0
1
kobotoolbox/kobocat:2.022.24ab15679454415
lxml@4.8.0
6.1.0
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
lxml@4.8.0
6.1.0
1
langgenius/dify-api:1.0.0066035f93856
lxml@5.3.1
6.1.0
1
langgenius/dify-api:0.6.11fca918260dd6
lxml@5.1.0
6.1.0
1
linuxserver/calibre-web:0.6.24241009026e6f
lxml@5.2.2
6.1.0
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
lxml@4.6.3
6.1.0
1
linuxserver/couchpotato:75e576ee-ls389cd8d5fb1ac
lxml@4.2.2
6.1.0
1
linuxserver/couchpotato:75e576ee-ls32c4d2766b9eb7
lxml@4.4.2
6.1.0
1
linuxserver/sickchill:v2020.08.07-1-ls40e48b479c1891
lxml@4.4.2
6.1.0
1
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
lxml@5.3.0
6.1.0
1
matrixdotorg/synapse:v1.53.0cb89c0f17ba1
lxml@4.8.0
6.1.0
1
matrixdotorg/synapse:v1.78.0def97fd537d8
lxml@4.9.2
6.1.0
1
mcronce/yadms-ftp:latestf820ef2e3c26
lxml@4.4.1
6.1.0
1
mcronce/yadms-web:latestc03c1c7f5aa9
lxml@4.4.1
6.1.0
1
microcks/microcks:0.8.0e3a3e0c67b09
lxml@3.2.1
6.1.0
1
mindsdb/mindsdb:latest163011c09299
lxml@5.3.0
6.1.0
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
lxml@4.9.1
6.1.0
1
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
lxml@4.4.1
6.1.0
1
nacos/nacos-server:1.4.1fe6e5688cdf3
lxml@3.2.1
6.1.0
1
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
lxml@4.2.5
6.1.0
1
netboxcommunity/netbox:v3.2.83d652dca5351
lxml@4.9.1
6.1.0
1
netboxcommunity/netbox:v3.7.8-2.8.09bf83b350a89
lxml@5.2.1
6.1.0
1
networktocode/nautobot:3.0-py3.13ed484336b1ad
lxml@6.0.2
6.1.0
1
ngoduykhanh/powerdns-admin:0.2.3099371dd9ba6
lxml@4.5.2
6.1.0
1
ngoduykhanh/powerdns-admin:latest9898a7cf37d2
lxml@4.6.5
6.1.0
1
opea/asr:1.025dd26d9cd09
lxml@5.3.0
6.1.0
1
opea/guardrails-tgi:1.0262c6048aab8
lxml@5.3.0
6.1.0
1
opea/guardrails-tgi:latestf68bec6a1271
lxml@5.3.0
6.1.0
1
opea/llm-docsum-tgi:1.002f9e8fa5d71
lxml@5.3.0
6.1.0
1
opea/speecht5:1.0249afad3d268
lxml@5.3.0
6.1.0
1
opea/tts:1.0257ae94709e9
lxml@5.3.0
6.1.0
1
opea/web-retriever-chroma:1.0fe08165d7770
lxml@5.3.0
6.1.0
1
openbas/caldera-server:5.1.0a277796d9724
lxml@4.9.4
6.1.0
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
lxml@5.4.0
6.1.0
1
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
lxml@6.0.2
6.1.0
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
lxml@6.0.0
6.1.0
1
opencsghq/label-studio:v2.5.047e22aa71870
lxml@5.3.0
6.1.0
1
opencsghq/label-studio:v2.4.0b4e849fcf94a
lxml@5.3.0
6.1.0
1
opendatacube/pipelines:wofs-1.225d810e8504b8
lxml@4.2.1
6.1.0
1
opendatacube/restcube:latest91870111837c
lxml@4.2.1
6.1.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.