StackRadar

CVE-2026-41066

High

Advisory

Published 21 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
163
of 17,781 indexed, latest versions
Container images
164
deployed by those charts
Fix available
1 of 2
affected packages

lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files

Carried by container images the latest versions of 163 of 17,781 indexed charts deploy, on 164 images.

Affected packageAffected versionsFixed inImages
lxmlpypi3.2.1, 3.6.4, 4.1.0, 4.2.1+32 more6.1.0164
lxmldeb4.8.0-1build1, 5.2.1-1, 5.4.0-1no fix listed3
OSV records
DEBIAN-CVE-2026-41066GHSA-vfmq-68hx-4jfwUBUNTU-CVE-2026-41066
Also known as
PYSEC-2026-87

Charts affected

163 by stars
ChartLatestAffected imagesRadar Score
assemblylineassemblylineVerified publisher7.4.172 of 12See more

assemblyline assemblyline 7.4.17

2 of the 12 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
cccs/assemblyline-socketio:4.7.4.stable1724646dbfd944
lxml@5.3.2
6.1.0
cccs/assemblyline-ui:4.7.4.stable171a7a103668f5
lxml@5.3.2
6.1.0

Open the chart page →

12,898
huebigdata-chartsVerified publisher1.0.41 of 2See more

hue bigdata-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
gethue/hue:4.10.05702b2c37ff9
lxml@4.6.3
6.1.0

Open the chart page →

22,891
couchpotatobryanalves0.3.01 of 1See more

couchpotato bryanalves 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
linuxserver/couchpotato:75e576ee-ls32c4d2766b9eb7
lxml@4.4.2
6.1.0

Open the chart page →

2,018
sickchillbryanalves0.3.01 of 1See more

sickchill bryanalves 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
linuxserver/sickchill:v2020.08.07-1-ls40e48b479c1891
lxml@4.4.2
6.1.0

Open the chart page →

2,504
sickragebryanalves0.1.01 of 1See more

sickrage bryanalves 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
bryanalves/sickrage:latest42f0a130001d
lxml@3.6.4
6.1.0

Open the chart page →

923
chat-searchchat-searchVerified publisher0.1.71 of 1See more

chat-search chat-search 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ghcr.io/hemslo/chat-search:latest39d48995a5bd
lxml@5.2.2
6.1.0

Open the chart page →

4,042
galaxy-stablecloudve2.0.01 of 5See more

galaxy-stable cloudve 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
galaxy/galaxy-init:v18.010267bad550e6
lxml@4.1.0
6.1.0

Open the chart page →

70,895
janisterminalcloudve0.1.01 of 2See more

janisterminal cloudve 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
cloudve/janis-terminal:latestaf56e77ca587
lxml@4.5.1
6.1.0

Open the chart page →

14,270
pulsarcloudve0.2.01 of 2See more

pulsar cloudve 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
lxml@5.4.0
6.1.0

Open the chart page →

6,162
pbcore-utilcluster-deploy0.0.11 of 1See more

pbcore-util cluster-deploy 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
lxml@6.0.2
6.1.0

Open the chart page →

9,128
couchpotatocronce0.0.11 of 1See more

couchpotato cronce 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
linuxserver/couchpotato:75e576ee-ls389cd8d5fb1ac
lxml@4.2.2
6.1.0

Open the chart page →

3,871
yadmscronce0.3.02 of 2See more

yadms cronce 0.3.0

2 of the 2 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
mcronce/yadms-ftp:latestf820ef2e3c26
lxml@4.4.1
6.1.0
mcronce/yadms-web:latestc03c1c7f5aa9
lxml@4.4.1
6.1.0

Open the chart page →

2,500
csghubcsghubVerified publisher2.4.33 of 34See more

csghub csghub 2.4.3

3 of the 34 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opencsghq/agenticflow:ee-v0.6-52f03fead54db
lxml@5.4.0
6.1.0
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
lxml@6.0.2
6.1.0
opencsghq/label-studio:v2.4.0b4e849fcf94a
lxml@5.3.0
6.1.0

Open the chart page →

58,897
csgshipcsghubVerified publisher0.4.61 of 10See more

csgship csghub 0.4.6

1 of the 10 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
lxml@6.0.0
6.1.0

Open the chart page →

11,335
dataflowcsghubVerified publisher2.5.01 of 7See more

dataflow csghub 2.5.0

1 of the 7 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opencsghq/label-studio:v2.5.047e22aa71870
lxml@5.3.0
6.1.0

Open the chart page →

6,632
home-assistantdamounVerified publisher1.1.01 of 1See more

home-assistant damoun 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
lxml@4.9.3
6.1.0

Open the chart page →

6,179
datacubedatacube-charts0.18.21 of 1See more

datacube datacube-charts 0.18.2

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opendatacube/wms:latest1b90cdf68831
lxml@4.2.1
6.1.0

Open the chart page →

27,728
datacube-datadatacube-charts0.2.61 of 1See more

datacube-data datacube-charts 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
lxml@4.5.2
6.1.0

Open the chart page →

18,863
datacube-indexdatacube-charts0.4.41 of 2See more

datacube-index datacube-charts 0.4.4

1 of the 2 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
lxml@5.3.0
6.1.0

Open the chart page →

6,123
datacube-owsdatacube-charts0.20.11 of 1See more

datacube-ows datacube-charts 0.20.1

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
lxml@5.3.0
6.1.0

Open the chart page →

5,974
datacube-processingdatacube-charts0.1.11 of 2See more

datacube-processing datacube-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opendatacube/pipelines:wofs-1.225d810e8504b8
lxml@4.2.1
6.1.0

Open the chart page →

22,405
datacube-wpsdatacube-charts0.9.01 of 1See more

datacube-wps datacube-charts 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opendatacube/wps:latest80df355a660b
lxml@5.3.2
6.1.0

Open the chart page →

6,172
restcubedatacube-charts0.2.91 of 1See more

restcube datacube-charts 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opendatacube/restcube:latest91870111837c
lxml@4.2.1
6.1.0

Open the chart page →

24,335
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
lxml@4.9.2
6.1.0

Open the chart page →

14,856
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
lxml@5.3.1
6.1.0

Open the chart page →

19,224
codecovdoubanVerified publisher0.2.41 of 8See more

codecov douban 0.2.4

1 of the 8 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
codecov/self-hosted-worker:24.4.1837f546b479b
lxml@4.9.1
6.1.0

Open the chart page →

24,917
rook-cephdtrdnk-helm-chartsVerified publisher0.0.11 of 2See more

rook-ceph dtrdnk-helm-charts 0.0.1

1 of the 2 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
rook/ceph:v1.19.2944a1dd70496
lxml@4.6.5
6.1.0

Open the chart page →

1,990
seafileeleksbai0.1.11 of 3See more

seafile eleksbai 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.106693911bcc40
lxml@4.9.1
6.1.0

Open the chart page →

25,122
datadog-apmfairwinds-incubator2.0.01 of 1See more

datadog-apm fairwinds-incubator 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
lxml@6.0.1
6.1.0

Open the chart page →

2,785
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
lxml@4.9.3
6.1.0

Open the chart page →

64,489
powerdnsfsdrw080.1.31 of 4See more

powerdns fsdrw08 0.1.3

1 of the 4 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:latest9898a7cf37d2
lxml@4.6.5
6.1.0

Open the chart page →

1,958
tandoorgabe565Verified publisher0.9.91 of 2See more

tandoor gabe565 0.9.9

1 of the 2 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
lxml@5.3.0
6.1.0

Open the chart page →

2,183
calibre-webgeek-cookbookVerified publisher8.4.21 of 1See more

calibre-web geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
linuxserver/calibre-web:version-0.6.12938810eca3d3
lxml@4.6.3
6.1.0

Open the chart page →

16,123
changedetection-iogeek-cookbookVerified publisher1.5.21 of 1See more

changedetection-io geek-cookbook 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.39.4f1ce4c56ccaa
lxml@4.6.4
6.1.0

Open the chart page →

1,950
nzbgetgeek-cookbookVerified publisher12.4.21 of 1See more

nzbget geek-cookbook 12.4.2

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
lxml@4.9.1
6.1.0

Open the chart page →

12,076
powerdns-admingeek-cookbookVerified publisher1.2.21 of 1See more

powerdns-admin geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
lxml@4.6.4
6.1.0

Open the chart page →

2,643
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
lxml@4.6.3
6.1.0

Open the chart page →

24,293
searxgeek-cookbookVerified publisher5.6.21 of 4See more

searx geek-cookbook 5.6.2

1 of the 4 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
searx/searx:1.0.0-211-968b28993dbb3a6d9419
lxml@4.6.3
6.1.0

Open the chart page →

7,470
skypilotgeek-cookbookVerified publisher0.0.11 of 3See more

skypilot geek-cookbook 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
lxml@6.0.2
6.1.0

Open the chart page →

8,923
opentelemetry-demogpg-dev0.33.81 of 27See more

opentelemetry-demo gpg-dev 0.33.8

1 of the 27 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
lxml@5.3.0
6.1.0

Open the chart page →

49,025
nacosheidaodageshiwoVerified publisher0.1.51 of 1See more

nacos heidaodageshiwo 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
nacos/nacos-server:v2.1.0dcf04549c6d7
lxml@3.2.1
6.1.0

Open the chart page →

3,978
home-assistanthelm-chart-roeiVerified publisher2025.3.01 of 1See more

home-assistant helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
lxml@5.3.0
6.1.0

Open the chart page →

4,647
weblatehelm-charts-nr0.3.21 of 3See more

weblate helm-charts-nr 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
lxml@4.5.2
6.1.0

Open the chart page →

7,984
ckanhelmforgeVerified publisher1.3.81 of 6See more

ckan helmforge 1.3.8

1 of the 6 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ckan/ckan-base-datapusher:0.0.2184d11924549f
lxml@5.3.2
6.1.0

Open the chart page →

9,920
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
openbas/caldera-server:5.1.0a277796d9724
lxml@4.9.4
6.1.0

Open the chart page →

25,017
heronheron0.20.5-incubating1 of 2See more

heron heron 0.20.5-incubating

1 of the 2 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
apache/bookkeeper:4.14.5a7d9970c148f
lxml@3.2.1
6.1.0

Open the chart page →

1,449
paperlesshomelabcihelmchartstestVerified publisher9.1.91 of 1See more

paperless homelabcihelmchartstest 9.1.9

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
lxml@4.9.3
6.1.0

Open the chart page →

16,384
ibm-business-automation-insights-devibm-charts3.2.03 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

3 of the 6 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
lxml@3.2.1
6.1.0
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
lxml@3.2.1
6.1.0
ibmcom/bai-flink-zookeeper-dev:19.0.258548034cf55
lxml@3.2.1
6.1.0

Open the chart page →

39,349
erpnextimprowisedVerified publisher3.3.01 of 3See more

erpnext improwised 3.3.0

1 of the 3 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
improwised/erpnext-worker:v13.4.197280b55cbd4
lxml@4.6.3
6.1.0

Open the chart page →

6,501
freeipaimprowisedVerified publisher0.4.11 of 1See more

freeipa improwised 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
freeipa/freeipa-server:fedora-37-4.10.1c87d77342bf5
lxml@4.9.1
6.1.0

Open the chart page →

1,218

Container images carrying it

164 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
opea/llm-tgi:1.00c25aab3f106
lxml@5.3.0
6.1.0
4
nacos/nacos-server:v2.1.0dcf04549c6d7
lxml@3.2.1
6.1.0
2
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
lxml@4.6.4
6.1.0
2
opea/embedding-tei:1.05c9639de61c1
lxml@5.3.0
6.1.0
2
opea/reranking-tei:1.0e48613afb191
lxml@5.3.0
6.1.0
2
opea/retriever-redis:1.0eb746b263705
lxml@5.3.0
6.1.0
2
opendatacube/ows:latest668cbb41473c
lxml@5.3.0
6.1.0
2
taigaio/taiga-back:latest4beed8f62c9f
lxml@6.0.2
6.1.0
2
weblate/weblate:4.2.2-169c160d37a3c
lxml@4.5.2
6.1.0
2
quay.io/cephcsi/cephcsi:v3.17.10b62db8afc9b
lxml@4.6.5
6.1.0
2
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
lxml@4.2.3
6.1.0
2
alerta/alerta-web:8.5.04786b9eaa606
lxml@4.6.3
6.1.0
1
amazon/dynamodb-local:1.20.01ed00881c937
lxml@3.2.1
6.1.0
1
amazon/dynamodb-local:1.12.08414d80019b0
lxml@3.2.1
6.1.0
1
apache/airflow:2.8.4-python3.964e58748b6b9
lxml@5.1.0
6.1.0
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
lxml@5.3.0
6.1.0
1
apache/airflow:2.8.1e5560ad0b86e
lxml@5.1.0
6.1.0
1
apache/bookkeeper:4.14.5a7d9970c148f
lxml@3.2.1
6.1.0
1
apache/hadoop:3af361b20bec0
lxml@3.2.1
6.1.0
1
apache/rocketmq:4.9.35ac2a4e0f627
lxml@3.2.1
6.1.0
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
lxml@5.3.2
6.1.0
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
lxml@6.0.2
6.1.0
1
bryanalves/sickrage:latest42f0a130001d
lxml@3.6.4
6.1.0
1
cccs/assemblyline-socketio:4.7.4.stable1724646dbfd944
lxml@5.3.2
6.1.0
1
cccs/assemblyline-ui:4.7.4.stable171a7a103668f5
lxml@5.3.2
6.1.0
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
lxml@6.0.4
6.1.0
1
ckan/ckan-base-datapusher:0.0.2184d11924549f
lxml@5.3.2
6.1.0
1
cloudve/janis-terminal:latestaf56e77ca587
lxml@4.5.1
6.1.0
1
codecov/self-hosted-worker:24.4.1837f546b479b
lxml@4.9.1
6.1.0
1
datadog/agent:7.22.08f20e56b5311
lxml@4.5.0
6.1.0
1
datadog/agent:6aad9994de6a7
lxml@4.9.2
6.1.0
1
datamate/seafile-professional:11.0.202dd66b722464
lxml@6.0.1
6.1.0
1
ddosify/selfhosted_backend:3.2.93c11e3182652
lxml@5.2.2
6.1.0
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
lxml@5.1.0
6.1.0
1
ddosify/selfhosted_hammermanager:2.0.2b796b8c73011
lxml@5.2.2
6.1.0
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
lxml@4.9.3
6.1.0
1
fossology/fossology:4.2.18bd1f22ba7bb
lxml@4.9.1
6.1.0
1
freeipa/freeipa-server:fedora-37-4.10.1c87d77342bf5
lxml@4.9.1
6.1.0
1
galaxy/galaxy-init:v18.010267bad550e6
lxml@4.1.0
6.1.0
1
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
lxml@5.4.0
6.1.0
1
geopython/pycsw:3.0.0-beta284662ea6b78b
lxml@6.0.2
6.1.0
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
lxml@4.5.2
6.1.0
1
gethue/hue:4.11.011b649636e68
lxml@4.9.1
6.1.0
1
gethue/hue:4.10.05702b2c37ff9
lxml@4.6.3
6.1.0
1
gethue/hue:latest7d5c1b9f8a79
lxml@4.9.1
6.1.0
1
gpappsoft/privacyidea-docker:3.12.2af7841adad26
lxml@5.3.1
6.1.0
1
grafana/oncall:v1.16.5499851658393
lxml@5.2.2
6.1.0
1
gristlabs/grist:0.7.96e71b1914a7e
lxml@4.6.3
6.1.0
1
hayk96/alerta-web:9.0.486377705e9e3
lxml@5.2.1
6.1.0
1
heartexlabs/label-studio:latestaa461572e8f9
lxml@5.3.0
6.1.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.