StackRadar

CVE-2026-41066

High

Advisory

Published 21 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
163
of 17,781 indexed, latest versions
Container images
164
deployed by those charts
Fix available
1 of 2
affected packages

lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files

Carried by container images the latest versions of 163 of 17,781 indexed charts deploy, on 164 images.

Affected packageAffected versionsFixed inImages
lxmlpypi3.2.1, 3.6.4, 4.1.0, 4.2.1+32 more6.1.0164
lxmldeb4.8.0-1build1, 5.2.1-1, 5.4.0-1no fix listed3
OSV records
DEBIAN-CVE-2026-41066GHSA-vfmq-68hx-4jfwUBUNTU-CVE-2026-41066
Also known as
PYSEC-2026-87

Charts affected

163 by stars
ChartLatestAffected imagesRadar Score
guardrails-usvctest-opea1.0.01 of 1See more

guardrails-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/guardrails-tgi:1.0262c6048aab8
lxml@5.3.0
6.1.0

Open the chart page →

5,221
llm-uservicetest-opea1.0.01 of 1See more

llm-uservice test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/llm-tgi:1.00c25aab3f106
lxml@5.3.0
6.1.0

Open the chart page →

4,720
reranking-usvctest-opea1.0.01 of 1See more

reranking-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/reranking-tei:1.0e48613afb191
lxml@5.3.0
6.1.0

Open the chart page →

4,985
retriever-usvctest-opea1.0.01 of 1See more

retriever-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/retriever-redis:1.0eb746b263705
lxml@5.3.0
6.1.0

Open the chart page →

5,198
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
lxml@5.3.0
6.1.0

Open the chart page →

9,616
ttstest-opea1.0.01 of 1See more

tts test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/tts:1.0257ae94709e9
lxml@5.3.0
6.1.0

Open the chart page →

4,377
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
lxml@5.3.0
6.1.0

Open the chart page →

5,350
synapsetranhailongVerified publisher0.1.01 of 2See more

synapse tranhailong 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.78.0def97fd537d8
lxml@4.9.2
6.1.0

Open the chart page →

3,164
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
lxml@4.8.0-1build1
lxml@4.8.0
no fix listed
6.1.0

Open the chart page →

13,459
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
lxml@5.2.2
6.1.0

Open the chart page →

7,628
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
lxml@4.2.3
6.1.0

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
lxml@4.2.3
6.1.0

Open the chart page →

11,784
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-41066.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
lxml@4.6.4
6.1.0

Open the chart page →

2,643

Container images carrying it

164 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
opea/llm-tgi:1.00c25aab3f106
lxml@5.3.0
6.1.0
4
nacos/nacos-server:v2.1.0dcf04549c6d7
lxml@3.2.1
6.1.0
2
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
lxml@4.6.4
6.1.0
2
opea/embedding-tei:1.05c9639de61c1
lxml@5.3.0
6.1.0
2
opea/reranking-tei:1.0e48613afb191
lxml@5.3.0
6.1.0
2
opea/retriever-redis:1.0eb746b263705
lxml@5.3.0
6.1.0
2
opendatacube/ows:latest668cbb41473c
lxml@5.3.0
6.1.0
2
taigaio/taiga-back:latest4beed8f62c9f
lxml@6.0.2
6.1.0
2
weblate/weblate:4.2.2-169c160d37a3c
lxml@4.5.2
6.1.0
2
quay.io/cephcsi/cephcsi:v3.17.10b62db8afc9b
lxml@4.6.5
6.1.0
2
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
lxml@4.2.3
6.1.0
2
alerta/alerta-web:8.5.04786b9eaa606
lxml@4.6.3
6.1.0
1
amazon/dynamodb-local:1.20.01ed00881c937
lxml@3.2.1
6.1.0
1
amazon/dynamodb-local:1.12.08414d80019b0
lxml@3.2.1
6.1.0
1
apache/airflow:2.8.4-python3.964e58748b6b9
lxml@5.1.0
6.1.0
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
lxml@5.3.0
6.1.0
1
apache/airflow:2.8.1e5560ad0b86e
lxml@5.1.0
6.1.0
1
apache/bookkeeper:4.14.5a7d9970c148f
lxml@3.2.1
6.1.0
1
apache/hadoop:3af361b20bec0
lxml@3.2.1
6.1.0
1
apache/rocketmq:4.9.35ac2a4e0f627
lxml@3.2.1
6.1.0
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
lxml@5.3.2
6.1.0
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
lxml@6.0.2
6.1.0
1
bryanalves/sickrage:latest42f0a130001d
lxml@3.6.4
6.1.0
1
cccs/assemblyline-socketio:4.7.4.stable1724646dbfd944
lxml@5.3.2
6.1.0
1
cccs/assemblyline-ui:4.7.4.stable171a7a103668f5
lxml@5.3.2
6.1.0
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
lxml@6.0.4
6.1.0
1
ckan/ckan-base-datapusher:0.0.2184d11924549f
lxml@5.3.2
6.1.0
1
cloudve/janis-terminal:latestaf56e77ca587
lxml@4.5.1
6.1.0
1
codecov/self-hosted-worker:24.4.1837f546b479b
lxml@4.9.1
6.1.0
1
datadog/agent:7.22.08f20e56b5311
lxml@4.5.0
6.1.0
1
datadog/agent:6aad9994de6a7
lxml@4.9.2
6.1.0
1
datamate/seafile-professional:11.0.202dd66b722464
lxml@6.0.1
6.1.0
1
ddosify/selfhosted_backend:3.2.93c11e3182652
lxml@5.2.2
6.1.0
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
lxml@5.1.0
6.1.0
1
ddosify/selfhosted_hammermanager:2.0.2b796b8c73011
lxml@5.2.2
6.1.0
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
lxml@4.9.3
6.1.0
1
fossology/fossology:4.2.18bd1f22ba7bb
lxml@4.9.1
6.1.0
1
freeipa/freeipa-server:fedora-37-4.10.1c87d77342bf5
lxml@4.9.1
6.1.0
1
galaxy/galaxy-init:v18.010267bad550e6
lxml@4.1.0
6.1.0
1
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
lxml@5.4.0
6.1.0
1
geopython/pycsw:3.0.0-beta284662ea6b78b
lxml@6.0.2
6.1.0
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
lxml@4.5.2
6.1.0
1
gethue/hue:4.11.011b649636e68
lxml@4.9.1
6.1.0
1
gethue/hue:4.10.05702b2c37ff9
lxml@4.6.3
6.1.0
1
gethue/hue:latest7d5c1b9f8a79
lxml@4.9.1
6.1.0
1
gpappsoft/privacyidea-docker:3.12.2af7841adad26
lxml@5.3.1
6.1.0
1
grafana/oncall:v1.16.5499851658393
lxml@5.2.2
6.1.0
1
gristlabs/grist:0.7.96e71b1914a7e
lxml@4.6.3
6.1.0
1
hayk96/alerta-web:9.0.486377705e9e3
lxml@5.2.1
6.1.0
1
heartexlabs/label-studio:latestaa461572e8f9
lxml@5.3.0
6.1.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.