StackRadar

CVE-2026-41066

High

Advisory

Published 21 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
163
of 17,781 indexed, latest versions
Container images
164
deployed by those charts
Fix available
1 of 2
affected packages

lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files

Carried by container images the latest versions of 163 of 17,781 indexed charts deploy, on 164 images.

Affected packageAffected versionsFixed inImages
lxmlpypi3.2.1, 3.6.4, 4.1.0, 4.2.1+32 more6.1.0164
lxmldeb4.8.0-1build1, 5.2.1-1, 5.4.0-1no fix listed3
OSV records
DEBIAN-CVE-2026-41066GHSA-vfmq-68hx-4jfwUBUNTU-CVE-2026-41066
Also known as
PYSEC-2026-87

Charts affected

163 by stars
ChartLatestAffected imagesRadar Score
guardrails-usvctest-opea1.0.01 of 1See more

guardrails-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/guardrails-tgi:1.0262c6048aab8
lxml@5.3.0
6.1.0

Open the chart page →

5,221
llm-uservicetest-opea1.0.01 of 1See more

llm-uservice test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/llm-tgi:1.00c25aab3f106
lxml@5.3.0
6.1.0

Open the chart page →

4,720
reranking-usvctest-opea1.0.01 of 1See more

reranking-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/reranking-tei:1.0e48613afb191
lxml@5.3.0
6.1.0

Open the chart page →

4,985
retriever-usvctest-opea1.0.01 of 1See more

retriever-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/retriever-redis:1.0eb746b263705
lxml@5.3.0
6.1.0

Open the chart page →

5,198
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
lxml@5.3.0
6.1.0

Open the chart page →

9,616
ttstest-opea1.0.01 of 1See more

tts test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/tts:1.0257ae94709e9
lxml@5.3.0
6.1.0

Open the chart page →

4,377
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
lxml@5.3.0
6.1.0

Open the chart page →

5,350
synapsetranhailongVerified publisher0.1.01 of 2See more

synapse tranhailong 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.78.0def97fd537d8
lxml@4.9.2
6.1.0

Open the chart page →

3,164
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
lxml@4.8.0-1build1
lxml@4.8.0
no fix listed
6.1.0

Open the chart page →

13,459
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
lxml@5.2.2
6.1.0

Open the chart page →

7,628
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
lxml@4.2.3
6.1.0

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
lxml@4.2.3
6.1.0

Open the chart page →

11,784
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
lxml@4.6.4
6.1.0

Open the chart page →

2,643

Container images carrying it

164 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
lxml@5.3.0
6.1.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
lxml@5.3.0
6.1.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
lxml@6.0.2
6.1.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
lxml@6.0.2
6.1.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
lxml@6.0.2
6.1.0
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
lxml@4.9.1
6.1.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
lxml@4.9.3
6.1.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
lxml@6.0.2
6.1.0
1
ghcr.io/shadrus/srebot:0.14.09b4415e937b2
lxml@6.0.3
6.1.0
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
lxml@6.0.2
6.1.0
1
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
lxml@5.3.0
6.1.0
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
lxml@6.0.2
6.1.0
1
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
lxml@6.0.1
6.1.0
1
quay.io/freeipa/freeipa-server:fedora-39-4.11.1d422ee50c2c3
lxml@4.9.3
6.1.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.