Количество 13
Количество 13
CVE-2026-41066
lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in the default configuration (with resolve_entities=True) allows untrusted XML input to read local files. Setting the resolve_entities option explicitly to resolve_entities='internal' or resolve_entities=False disables the local file access. This vulnerability is fixed in 6.1.0.
CVE-2026-41066
lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in the default configuration (with resolve_entities=True) allows untrusted XML input to read local files. Setting the resolve_entities option explicitly to resolve_entities='internal' or resolve_entities=False disables the local file access. This vulnerability is fixed in 6.1.0.
CVE-2026-41066
lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in the default configuration (with resolve_entities=True) allows untrusted XML input to read local files. Setting the resolve_entities option explicitly to resolve_entities='internal' or resolve_entities=False disables the local file access. This vulnerability is fixed in 6.1.0.
CVE-2026-41066
lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files
CVE-2026-41066
lxml is a library for processing XML and HTML in the Python language. ...
openSUSE-SU-2026:20737-1
Security update for python-lxml
SUSE-SU-2026:2754-1
Security update for python3-lxml
SUSE-SU-2026:2752-1
Security update for python3-lxml
SUSE-SU-2026:2729-1
Security update for python-lxml
SUSE-SU-2026:2728-1
Security update for python-lxml
GHSA-vfmq-68hx-4jfw
lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files
BDU:2026-09700
Уязвимость функции etree.iterparse() и ETCompatXMLParser() библиотеки для обработки разметки XML и HTML Lxml, позволяющая нарушителю читать произвольные файлы
ROS-20260622-73-0055
Уязвимость python-lxml
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-41066 lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in the default configuration (with resolve_entities=True) allows untrusted XML input to read local files. Setting the resolve_entities option explicitly to resolve_entities='internal' or resolve_entities=False disables the local file access. This vulnerability is fixed in 6.1.0. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-41066 lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in the default configuration (with resolve_entities=True) allows untrusted XML input to read local files. Setting the resolve_entities option explicitly to resolve_entities='internal' or resolve_entities=False disables the local file access. This vulnerability is fixed in 6.1.0. | CVSS3: 5.9 | 0% Низкий | 3 месяца назад | |
CVE-2026-41066 lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in the default configuration (with resolve_entities=True) allows untrusted XML input to read local files. Setting the resolve_entities option explicitly to resolve_entities='internal' or resolve_entities=False disables the local file access. This vulnerability is fixed in 6.1.0. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-41066 lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files | 0% Низкий | 3 месяца назад | ||
CVE-2026-41066 lxml is a library for processing XML and HTML in the Python language. ... | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
openSUSE-SU-2026:20737-1 Security update for python-lxml | 0% Низкий | 3 месяца назад | ||
SUSE-SU-2026:2754-1 Security update for python3-lxml | 0% Низкий | 30 дней назад | ||
SUSE-SU-2026:2752-1 Security update for python3-lxml | 0% Низкий | 30 дней назад | ||
SUSE-SU-2026:2729-1 Security update for python-lxml | 0% Низкий | около 1 месяца назад | ||
SUSE-SU-2026:2728-1 Security update for python-lxml | 0% Низкий | около 1 месяца назад | ||
GHSA-vfmq-68hx-4jfw lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
BDU:2026-09700 Уязвимость функции etree.iterparse() и ETCompatXMLParser() библиотеки для обработки разметки XML и HTML Lxml, позволяющая нарушителю читать произвольные файлы | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
ROS-20260622-73-0055 Уязвимость python-lxml | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу