StackRadar

CVE-2026-41066

High

Advisory

Published 21 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
163
of 17,781 indexed, latest versions
Container images
164
deployed by those charts
Fix available
1 of 2
affected packages

lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files

Carried by container images the latest versions of 163 of 17,781 indexed charts deploy, on 164 images.

Affected packageAffected versionsFixed inImages
lxmlpypi3.2.1, 3.6.4, 4.1.0, 4.2.1+32 more6.1.0164
lxmldeb4.8.0-1build1, 5.2.1-1, 5.4.0-1no fix listed3
OSV records
DEBIAN-CVE-2026-41066GHSA-vfmq-68hx-4jfwUBUNTU-CVE-2026-41066
Also known as
PYSEC-2026-87

Charts affected

163 by stars
ChartLatestAffected imagesRadar Score
guardrails-usvctest-opea1.0.01 of 1See more

guardrails-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/guardrails-tgi:1.0262c6048aab8
lxml@5.3.0
6.1.0

Open the chart page →

5,221
llm-uservicetest-opea1.0.01 of 1See more

llm-uservice test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/llm-tgi:1.00c25aab3f106
lxml@5.3.0
6.1.0

Open the chart page →

4,720
reranking-usvctest-opea1.0.01 of 1See more

reranking-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/reranking-tei:1.0e48613afb191
lxml@5.3.0
6.1.0

Open the chart page →

4,985
retriever-usvctest-opea1.0.01 of 1See more

retriever-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/retriever-redis:1.0eb746b263705
lxml@5.3.0
6.1.0

Open the chart page →

5,198
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
lxml@5.3.0
6.1.0

Open the chart page →

9,616
ttstest-opea1.0.01 of 1See more

tts test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/tts:1.0257ae94709e9
lxml@5.3.0
6.1.0

Open the chart page →

4,377
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
lxml@5.3.0
6.1.0

Open the chart page →

5,350
synapsetranhailongVerified publisher0.1.01 of 2See more

synapse tranhailong 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.78.0def97fd537d8
lxml@4.9.2
6.1.0

Open the chart page →

3,164
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
lxml@4.8.0-1build1
lxml@4.8.0
no fix listed
6.1.0

Open the chart page →

13,459
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
lxml@5.2.2
6.1.0

Open the chart page →

7,628
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
lxml@4.2.3
6.1.0

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
lxml@4.2.3
6.1.0

Open the chart page →

11,784
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
lxml@4.6.4
6.1.0

Open the chart page →

2,643

Container images carrying it

164 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
opendatacube/wms:latest1b90cdf68831
lxml@4.2.1
6.1.0
1
opendatacube/wps:latest80df355a660b
lxml@5.3.2
6.1.0
1
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
lxml@4.6.2
6.1.0
1
openvpn/openvpn-as:latest2253c10ec652
lxml@5.2.1-1
lxml@5.2.1
no fix listed
6.1.0
1
pschiffe/pdns-admin:0.4.137ebba8c2b8f
lxml@4.6.5
6.1.0
1
rook/ceph:v1.20.72f970c425617
lxml@4.6.5
6.1.0
1
rook/ceph:v1.19.2944a1dd70496
lxml@4.6.5
6.1.0
1
saidsef/scapy-containerised:v2025.02f17f7c435891
lxml@5.3.1
6.1.0
1
seafileltd/seafile-mc:9.0.106693911bcc40
lxml@4.9.1
6.1.0
1
seafileltd/seafile-mc:10.0.170628f29c663
lxml@4.9.2
6.1.0
1
seafileltd/seafile-mc:9.0.97ac833196f60
lxml@4.9.1
6.1.0
1
seafileltd/seafile-mc:11.0.12d0c66e4621bd
lxml@5.3.0
6.1.0
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
lxml@4.6.3
6.1.0
1
searx/searx:1.0.0-211-968b28993dbb3a6d9419
lxml@4.6.3
6.1.0
1
stashapp/stash:v0.31.1df744af5a0c9
lxml@6.0.2
6.1.0
1
statcan/ckan:2.93921305425b8
lxml@4.4.2
6.1.0
1
svtechnmaa/svtech_icinga2:v1.1.667be2aba9436
lxml@5.1.0
6.1.0
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
lxml@4.9.0
6.1.0
1
taigaio/taiga-back:6.4.29f97323cc150
lxml@4.6.3
6.1.0
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
lxml@4.8.0-1build1
lxml@4.8.0
no fix listed
6.1.0
1
vabene1111/recipes:2.3.50f8d061895e9
lxml@6.0.2
6.1.0
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
lxml@4.7.1
6.1.0
1
voltha/voltha-cli:1.6.0c4e41e92f046
lxml@3.6.4
6.1.0
1
voltha/voltha-netconf:1.6.037f80524c207
lxml@3.6.4
6.1.0
1
voltha/voltha-ofagent:1.6.09ee8c1f4428c
lxml@3.6.4
6.1.0
1
voltha/voltha-tester:1.7.0655c3048a602
lxml@3.6.4
6.1.0
1
voltha/voltha-voltha:1.6.0ff596b62de59
lxml@3.6.4
6.1.0
1
weblate/weblate:3.11.3-182848df56ecd
lxml@4.3.2
6.1.0
1
ghcr.io/blakeblackshear/frigate:0.14.122e3d0b486df
lxml@5.3.0
6.1.0
1
ghcr.io/blakeblackshear/frigate:0.13.07a5244e4c8dc
lxml@5.1.0
6.1.0
1
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
lxml@6.0.2
6.1.0
1
ghcr.io/dgtlmoon/changedetection.io:0.39.4f1ce4c56ccaa
lxml@4.6.4
6.1.0
1
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
lxml@5.2.2
6.1.0
1
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
lxml@6.0.2
6.1.0
1
ghcr.io/grycap/im:latest06a16d4f279f
lxml@6.0.2
6.1.0
1
ghcr.io/hemslo/chat-search:latest39d48995a5bd
lxml@5.2.2
6.1.0
1
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
lxml@5.3.0
6.1.0
1
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
lxml@6.0.1
6.1.0
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
lxml@4.8.0
6.1.0
1
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
lxml@4.9.3
6.1.0
1
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
lxml@6.0.1
6.1.0
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
lxml@4.8.0
6.1.0
1
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
lxml@4.9.1
6.1.0
1
ghcr.io/libretime/libretime-playout:latest71a8706531aa
lxml@5.4.0
6.1.0
1
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
lxml@5.3.2
6.1.0
1
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
lxml@5.2.2
6.1.0
1
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
lxml@6.0.1
6.1.0
1
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
lxml@5.1.0
6.1.0
1
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
lxml@6.0.2
6.1.0
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
lxml@6.0.2
6.1.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.