StackRadar

CVE-2026-41066

High

Advisory

Published 21 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
163
of 17,781 indexed, latest versions
Container images
164
deployed by those charts
Fix available
1 of 2
affected packages

lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files

Carried by container images the latest versions of 163 of 17,781 indexed charts deploy, on 164 images.

Affected packageAffected versionsFixed inImages
lxmlpypi3.2.1, 3.6.4, 4.1.0, 4.2.1+32 more6.1.0164
lxmldeb4.8.0-1build1, 5.2.1-1, 5.4.0-1no fix listed3
OSV records
DEBIAN-CVE-2026-41066GHSA-vfmq-68hx-4jfwUBUNTU-CVE-2026-41066
Also known as
PYSEC-2026-87

Charts affected

163 by stars
ChartLatestAffected imagesRadar Score
assemblylineassemblylineVerified publisher7.4.172 of 12See more

assemblyline assemblyline 7.4.17

2 of the 12 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
cccs/assemblyline-socketio:4.7.4.stable1724646dbfd944
lxml@5.3.2
6.1.0
cccs/assemblyline-ui:4.7.4.stable171a7a103668f5
lxml@5.3.2
6.1.0

Open the chart page →

12,898
huebigdata-chartsVerified publisher1.0.41 of 2See more

hue bigdata-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
gethue/hue:4.10.05702b2c37ff9
lxml@4.6.3
6.1.0

Open the chart page →

22,891
couchpotatobryanalves0.3.01 of 1See more

couchpotato bryanalves 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
linuxserver/couchpotato:75e576ee-ls32c4d2766b9eb7
lxml@4.4.2
6.1.0

Open the chart page →

2,018
sickchillbryanalves0.3.01 of 1See more

sickchill bryanalves 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
linuxserver/sickchill:v2020.08.07-1-ls40e48b479c1891
lxml@4.4.2
6.1.0

Open the chart page →

2,504
sickragebryanalves0.1.01 of 1See more

sickrage bryanalves 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
bryanalves/sickrage:latest42f0a130001d
lxml@3.6.4
6.1.0

Open the chart page →

923
chat-searchchat-searchVerified publisher0.1.71 of 1See more

chat-search chat-search 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ghcr.io/hemslo/chat-search:latest39d48995a5bd
lxml@5.2.2
6.1.0

Open the chart page →

4,042
galaxy-stablecloudve2.0.01 of 5See more

galaxy-stable cloudve 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
galaxy/galaxy-init:v18.010267bad550e6
lxml@4.1.0
6.1.0

Open the chart page →

70,895
janisterminalcloudve0.1.01 of 2See more

janisterminal cloudve 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
cloudve/janis-terminal:latestaf56e77ca587
lxml@4.5.1
6.1.0

Open the chart page →

14,270
pulsarcloudve0.2.01 of 2See more

pulsar cloudve 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
lxml@5.4.0
6.1.0

Open the chart page →

6,162
pbcore-utilcluster-deploy0.0.11 of 1See more

pbcore-util cluster-deploy 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
lxml@6.0.2
6.1.0

Open the chart page →

9,128
couchpotatocronce0.0.11 of 1See more

couchpotato cronce 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
linuxserver/couchpotato:75e576ee-ls389cd8d5fb1ac
lxml@4.2.2
6.1.0

Open the chart page →

3,871
yadmscronce0.3.02 of 2See more

yadms cronce 0.3.0

2 of the 2 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
mcronce/yadms-ftp:latestf820ef2e3c26
lxml@4.4.1
6.1.0
mcronce/yadms-web:latestc03c1c7f5aa9
lxml@4.4.1
6.1.0

Open the chart page →

2,500
csghubcsghubVerified publisher2.4.33 of 34See more

csghub csghub 2.4.3

3 of the 34 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opencsghq/agenticflow:ee-v0.6-52f03fead54db
lxml@5.4.0
6.1.0
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
lxml@6.0.2
6.1.0
opencsghq/label-studio:v2.4.0b4e849fcf94a
lxml@5.3.0
6.1.0

Open the chart page →

58,897
csgshipcsghubVerified publisher0.4.61 of 10See more

csgship csghub 0.4.6

1 of the 10 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
lxml@6.0.0
6.1.0

Open the chart page →

11,335
dataflowcsghubVerified publisher2.5.01 of 7See more

dataflow csghub 2.5.0

1 of the 7 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opencsghq/label-studio:v2.5.047e22aa71870
lxml@5.3.0
6.1.0

Open the chart page →

6,632
home-assistantdamounVerified publisher1.1.01 of 1See more

home-assistant damoun 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
lxml@4.9.3
6.1.0

Open the chart page →

6,179
datacubedatacube-charts0.18.21 of 1See more

datacube datacube-charts 0.18.2

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opendatacube/wms:latest1b90cdf68831
lxml@4.2.1
6.1.0

Open the chart page →

27,728
datacube-datadatacube-charts0.2.61 of 1See more

datacube-data datacube-charts 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
lxml@4.5.2
6.1.0

Open the chart page →

18,863
datacube-indexdatacube-charts0.4.41 of 2See more

datacube-index datacube-charts 0.4.4

1 of the 2 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
lxml@5.3.0
6.1.0

Open the chart page →

6,123
datacube-owsdatacube-charts0.20.11 of 1See more

datacube-ows datacube-charts 0.20.1

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
lxml@5.3.0
6.1.0

Open the chart page →

5,974
datacube-processingdatacube-charts0.1.11 of 2See more

datacube-processing datacube-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opendatacube/pipelines:wofs-1.225d810e8504b8
lxml@4.2.1
6.1.0

Open the chart page →

22,405
datacube-wpsdatacube-charts0.9.01 of 1See more

datacube-wps datacube-charts 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opendatacube/wps:latest80df355a660b
lxml@5.3.2
6.1.0

Open the chart page →

6,172
restcubedatacube-charts0.2.91 of 1See more

restcube datacube-charts 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opendatacube/restcube:latest91870111837c
lxml@4.2.1
6.1.0

Open the chart page →

24,335
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
lxml@4.9.2
6.1.0

Open the chart page →

14,856
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
lxml@5.3.1
6.1.0

Open the chart page →

19,224
codecovdoubanVerified publisher0.2.41 of 8See more

codecov douban 0.2.4

1 of the 8 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
codecov/self-hosted-worker:24.4.1837f546b479b
lxml@4.9.1
6.1.0

Open the chart page →

24,917
rook-cephdtrdnk-helm-chartsVerified publisher0.0.11 of 2See more

rook-ceph dtrdnk-helm-charts 0.0.1

1 of the 2 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
rook/ceph:v1.19.2944a1dd70496
lxml@4.6.5
6.1.0

Open the chart page →

1,990
seafileeleksbai0.1.11 of 3See more

seafile eleksbai 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.106693911bcc40
lxml@4.9.1
6.1.0

Open the chart page →

25,122
datadog-apmfairwinds-incubator2.0.01 of 1See more

datadog-apm fairwinds-incubator 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
lxml@6.0.1
6.1.0

Open the chart page →

2,785
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
lxml@4.9.3
6.1.0

Open the chart page →

64,489
powerdnsfsdrw080.1.31 of 4See more

powerdns fsdrw08 0.1.3

1 of the 4 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:latest9898a7cf37d2
lxml@4.6.5
6.1.0

Open the chart page →

1,958
tandoorgabe565Verified publisher0.9.91 of 2See more

tandoor gabe565 0.9.9

1 of the 2 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
lxml@5.3.0
6.1.0

Open the chart page →

2,183
calibre-webgeek-cookbookVerified publisher8.4.21 of 1See more

calibre-web geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
linuxserver/calibre-web:version-0.6.12938810eca3d3
lxml@4.6.3
6.1.0

Open the chart page →

16,123
changedetection-iogeek-cookbookVerified publisher1.5.21 of 1See more

changedetection-io geek-cookbook 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.39.4f1ce4c56ccaa
lxml@4.6.4
6.1.0

Open the chart page →

1,950
nzbgetgeek-cookbookVerified publisher12.4.21 of 1See more

nzbget geek-cookbook 12.4.2

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
lxml@4.9.1
6.1.0

Open the chart page →

12,076
powerdns-admingeek-cookbookVerified publisher1.2.21 of 1See more

powerdns-admin geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
lxml@4.6.4
6.1.0

Open the chart page →

2,643
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
lxml@4.6.3
6.1.0

Open the chart page →

24,293
searxgeek-cookbookVerified publisher5.6.21 of 4See more

searx geek-cookbook 5.6.2

1 of the 4 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
searx/searx:1.0.0-211-968b28993dbb3a6d9419
lxml@4.6.3
6.1.0

Open the chart page →

7,470
skypilotgeek-cookbookVerified publisher0.0.11 of 3See more

skypilot geek-cookbook 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
lxml@6.0.2
6.1.0

Open the chart page →

8,923
opentelemetry-demogpg-dev0.33.81 of 27See more

opentelemetry-demo gpg-dev 0.33.8

1 of the 27 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
lxml@5.3.0
6.1.0

Open the chart page →

49,025
nacosheidaodageshiwoVerified publisher0.1.51 of 1See more

nacos heidaodageshiwo 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
nacos/nacos-server:v2.1.0dcf04549c6d7
lxml@3.2.1
6.1.0

Open the chart page →

3,978
home-assistanthelm-chart-roeiVerified publisher2025.3.01 of 1See more

home-assistant helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
lxml@5.3.0
6.1.0

Open the chart page →

4,647
weblatehelm-charts-nr0.3.21 of 3See more

weblate helm-charts-nr 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
lxml@4.5.2
6.1.0

Open the chart page →

7,984
ckanhelmforgeVerified publisher1.3.81 of 6See more

ckan helmforge 1.3.8

1 of the 6 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ckan/ckan-base-datapusher:0.0.2184d11924549f
lxml@5.3.2
6.1.0

Open the chart page →

9,920
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
openbas/caldera-server:5.1.0a277796d9724
lxml@4.9.4
6.1.0

Open the chart page →

25,017
heronheron0.20.5-incubating1 of 2See more

heron heron 0.20.5-incubating

1 of the 2 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
apache/bookkeeper:4.14.5a7d9970c148f
lxml@3.2.1
6.1.0

Open the chart page →

1,449
paperlesshomelabcihelmchartstestVerified publisher9.1.91 of 1See more

paperless homelabcihelmchartstest 9.1.9

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
lxml@4.9.3
6.1.0

Open the chart page →

16,384
ibm-business-automation-insights-devibm-charts3.2.03 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

3 of the 6 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
lxml@3.2.1
6.1.0
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
lxml@3.2.1
6.1.0
ibmcom/bai-flink-zookeeper-dev:19.0.258548034cf55
lxml@3.2.1
6.1.0

Open the chart page →

39,349
erpnextimprowisedVerified publisher3.3.01 of 3See more

erpnext improwised 3.3.0

1 of the 3 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
improwised/erpnext-worker:v13.4.197280b55cbd4
lxml@4.6.3
6.1.0

Open the chart page →

6,501
freeipaimprowisedVerified publisher0.4.11 of 1See more

freeipa improwised 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
freeipa/freeipa-server:fedora-37-4.10.1c87d77342bf5
lxml@4.9.1
6.1.0

Open the chart page →

1,218

Container images carrying it

164 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
lxml@5.3.0
6.1.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
lxml@5.3.0
6.1.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
lxml@6.0.2
6.1.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
lxml@6.0.2
6.1.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
lxml@6.0.2
6.1.0
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
lxml@4.9.1
6.1.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
lxml@4.9.3
6.1.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
lxml@6.0.2
6.1.0
1
ghcr.io/shadrus/srebot:0.14.09b4415e937b2
lxml@6.0.3
6.1.0
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
lxml@6.0.2
6.1.0
1
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
lxml@5.3.0
6.1.0
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
lxml@6.0.2
6.1.0
1
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
lxml@6.0.1
6.1.0
1
quay.io/freeipa/freeipa-server:fedora-39-4.11.1d422ee50c2c3
lxml@4.9.3
6.1.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.