Skip to content

avm, sonos, yamaha: update lxml parser due to CVE-2026-41066#1033

Open
Morg42 wants to merge 1 commit intosmarthomeNG:developfrom
Morg42:lxml
Open

avm, sonos, yamaha: update lxml parser due to CVE-2026-41066#1033
Morg42 wants to merge 1 commit intosmarthomeNG:developfrom
Morg42:lxml

Conversation

@Morg42
Copy link
Copy Markdown
Member

@Morg42 Morg42 commented Apr 27, 2026

ref: https://github.com/advisories/GHSA-vfmq-68hx-4jfw/dependabot?query=user%3AsmarthomeNG

Added (new) default parser with resolve_entities='internal' set, otherwise unchanged.

Cannot test plugins, maintainers please check if they run properly.

@Morg42 Morg42 requested review from aschwith, bmxp and sisamiwe April 27, 2026 13:28
@aschwith
Copy link
Copy Markdown
Contributor

aschwith commented May 3, 2026

Thanks for taking care of this. I am running the changes for sonos now in my productive setup and provide feedback soon.

Copy link
Copy Markdown
Contributor

@aschwith aschwith left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still works as designed for the sonos plugin. Thx for fixing this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants