CVE-2026-41066Disclosure(lxml / lxml)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch lxml lxml systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in the default configuration (with resolve_entities=True) allows untrusted XML input to read local files. Setting the resolve_entities option explicitly to resolve_entities='internal' or resolve_entities=False disables the local file access. This vulnerability is fixed in 6.1.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-611

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • lxml

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-24); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
lxml

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-24: 1Mentions · 2026-05-01: 1Patch / Workaround · 2026-05-01: 1Technical Details · 2026-04-24: 104-2405-01
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-04-241
Disclosure1
2026-05-011
Patch1
Full discourse2 posts
  • RazzReport@RazzReport
    Patch

    `OpenHands/OpenHands` shipped v1.7.0 with `SANDBOX_KVM_ENABLED` for hardware-accelerated virtualization. Concurrently, the repo branched fixes for CVE-2026-41066, addressing security alongside a major performance boost for agent sandboxes.

    Post summary

    OpenHands released v1.7.0 and applied a patch for CVE‑2026‑41066, adding hardware‑accelerated virtualization and performance gains to agent sandboxes.

    1000039
    6 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41066 lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in the default configuration (with resolve_entit… https://www.cve.org/CVERecord?id=CVE-2026-41066

    Post summary

    The post mentions CVE‑2026‑41066 for the lxml Python library, providing minimal technical details about the affected configuration but lacking proof‑of‑concept, exploit code, patch information, or evidence of active exploitation.

    0000039
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applxmllxml---

Explore more