StackRadar

CVE-2026-41066

High

Advisory

Published 21 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
163
of 17,781 indexed, latest versions
Container images
164
deployed by those charts
Fix available
1 of 2
affected packages

lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files

Carried by container images the latest versions of 163 of 17,781 indexed charts deploy, on 164 images.

Affected packageAffected versionsFixed inImages
lxmlpypi3.2.1, 3.6.4, 4.1.0, 4.2.1+32 more6.1.0164
lxmldeb4.8.0-1build1, 5.2.1-1, 5.4.0-1no fix listed3
OSV records
DEBIAN-CVE-2026-41066GHSA-vfmq-68hx-4jfwUBUNTU-CVE-2026-41066
Also known as
PYSEC-2026-87

Charts affected

163 by stars
ChartLatestAffected imagesRadar Score
guardrails-usvctest-opea1.0.01 of 1See more

guardrails-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/guardrails-tgi:1.0262c6048aab8
lxml@5.3.0
6.1.0

Open the chart page →

5,221
llm-uservicetest-opea1.0.01 of 1See more

llm-uservice test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/llm-tgi:1.00c25aab3f106
lxml@5.3.0
6.1.0

Open the chart page →

4,720
reranking-usvctest-opea1.0.01 of 1See more

reranking-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/reranking-tei:1.0e48613afb191
lxml@5.3.0
6.1.0

Open the chart page →

4,985
retriever-usvctest-opea1.0.01 of 1See more

retriever-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/retriever-redis:1.0eb746b263705
lxml@5.3.0
6.1.0

Open the chart page →

5,198
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
lxml@5.3.0
6.1.0

Open the chart page →

9,616
ttstest-opea1.0.01 of 1See more

tts test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/tts:1.0257ae94709e9
lxml@5.3.0
6.1.0

Open the chart page →

4,377
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
lxml@5.3.0
6.1.0

Open the chart page →

5,350
synapsetranhailongVerified publisher0.1.01 of 2See more

synapse tranhailong 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.78.0def97fd537d8
lxml@4.9.2
6.1.0

Open the chart page →

3,164
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
lxml@4.8.0-1build1
lxml@4.8.0
no fix listed
6.1.0

Open the chart page →

13,459
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
lxml@5.2.2
6.1.0

Open the chart page →

7,628
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
lxml@4.2.3
6.1.0

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
lxml@4.2.3
6.1.0

Open the chart page →

11,784
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
lxml@4.6.4
6.1.0

Open the chart page →

2,643

Container images carrying it

164 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
hkotel/mealie:api-v1.0.0beta-2a7e6b6abe087
lxml@4.8.0
6.1.0
1
homeassistant/home-assistant:2023.10.3021e2afc6e57
lxml@4.9.3
6.1.0
1
homeassistant/home-assistant:2023.12.48d000332b09b
lxml@4.9.3
6.1.0
1
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
lxml@3.2.1
6.1.0
1
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
lxml@3.2.1
6.1.0
1
ibmcom/bai-flink-zookeeper-dev:19.0.258548034cf55
lxml@3.2.1
6.1.0
1
improwised/erpnext-worker:v13.4.197280b55cbd4
lxml@4.6.3
6.1.0
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
lxml@6.0.2
6.1.0
1
inventree/inventree:1.5.4a946ec09da3e
lxml@5.4.0-1
lxml@5.4.0
no fix listed
6.1.0
1
keitaro/ckan-datapusher:0.0.175bf1a45f45c1
lxml@4.5.2
6.1.0
1
kobotoolbox/kobocat:2.022.24ab15679454415
lxml@4.8.0
6.1.0
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
lxml@4.8.0
6.1.0
1
langgenius/dify-api:1.0.0066035f93856
lxml@5.3.1
6.1.0
1
langgenius/dify-api:0.6.11fca918260dd6
lxml@5.1.0
6.1.0
1
linuxserver/calibre-web:0.6.24241009026e6f
lxml@5.2.2
6.1.0
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
lxml@4.6.3
6.1.0
1
linuxserver/couchpotato:75e576ee-ls389cd8d5fb1ac
lxml@4.2.2
6.1.0
1
linuxserver/couchpotato:75e576ee-ls32c4d2766b9eb7
lxml@4.4.2
6.1.0
1
linuxserver/sickchill:v2020.08.07-1-ls40e48b479c1891
lxml@4.4.2
6.1.0
1
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
lxml@5.3.0
6.1.0
1
matrixdotorg/synapse:v1.53.0cb89c0f17ba1
lxml@4.8.0
6.1.0
1
matrixdotorg/synapse:v1.78.0def97fd537d8
lxml@4.9.2
6.1.0
1
mcronce/yadms-ftp:latestf820ef2e3c26
lxml@4.4.1
6.1.0
1
mcronce/yadms-web:latestc03c1c7f5aa9
lxml@4.4.1
6.1.0
1
microcks/microcks:0.8.0e3a3e0c67b09
lxml@3.2.1
6.1.0
1
mindsdb/mindsdb:latest163011c09299
lxml@5.3.0
6.1.0
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
lxml@4.9.1
6.1.0
1
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
lxml@4.4.1
6.1.0
1
nacos/nacos-server:1.4.1fe6e5688cdf3
lxml@3.2.1
6.1.0
1
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
lxml@4.2.5
6.1.0
1
netboxcommunity/netbox:v3.2.83d652dca5351
lxml@4.9.1
6.1.0
1
netboxcommunity/netbox:v3.7.8-2.8.09bf83b350a89
lxml@5.2.1
6.1.0
1
networktocode/nautobot:3.0-py3.13ed484336b1ad
lxml@6.0.2
6.1.0
1
ngoduykhanh/powerdns-admin:0.2.3099371dd9ba6
lxml@4.5.2
6.1.0
1
ngoduykhanh/powerdns-admin:latest9898a7cf37d2
lxml@4.6.5
6.1.0
1
opea/asr:1.025dd26d9cd09
lxml@5.3.0
6.1.0
1
opea/guardrails-tgi:1.0262c6048aab8
lxml@5.3.0
6.1.0
1
opea/guardrails-tgi:latestf68bec6a1271
lxml@5.3.0
6.1.0
1
opea/llm-docsum-tgi:1.002f9e8fa5d71
lxml@5.3.0
6.1.0
1
opea/speecht5:1.0249afad3d268
lxml@5.3.0
6.1.0
1
opea/tts:1.0257ae94709e9
lxml@5.3.0
6.1.0
1
opea/web-retriever-chroma:1.0fe08165d7770
lxml@5.3.0
6.1.0
1
openbas/caldera-server:5.1.0a277796d9724
lxml@4.9.4
6.1.0
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
lxml@5.4.0
6.1.0
1
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
lxml@6.0.2
6.1.0
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
lxml@6.0.0
6.1.0
1
opencsghq/label-studio:v2.5.047e22aa71870
lxml@5.3.0
6.1.0
1
opencsghq/label-studio:v2.4.0b4e849fcf94a
lxml@5.3.0
6.1.0
1
opendatacube/pipelines:wofs-1.225d810e8504b8
lxml@4.2.1
6.1.0
1
opendatacube/restcube:latest91870111837c
lxml@4.2.1
6.1.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.