Agent version
7.78.2
Bug Report
CVE-2026-41066: lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files
The python library lxml version 6.0.1 in /opt/datadog-agent/embedded/lib/python3.13/site-packages/lxml-6.0.1.dist-info/METADATA is vulnerable to CVE-2026-41066, which exists in versions < 6.1.0.
This can be fixed by updating the lxml package to version 6.1.0 or higher.
Related resources:
A public exploit for this vulnerability in lxml is available as well.
Reproduction Steps
No response
Agent configuration
No response
Operating System
No response
Other environment details
No response
Agent version
7.78.2
Bug Report
CVE-2026-41066: lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files
The python library
lxmlversion6.0.1in/opt/datadog-agent/embedded/lib/python3.13/site-packages/lxml-6.0.1.dist-info/METADATAis vulnerable to CVE-2026-41066, which exists in versions < 6.1.0.This can be fixed by updating the
lxmlpackage to version6.1.0or higher.Related resources:
A public exploit for this vulnerability in
lxmlis available as well.Reproduction Steps
No response
Agent configuration
No response
Operating System
No response
Other environment details
No response