From: Darsh Kelaiya <[email protected]>

This patch applies the upstream fix as referenced in [2], using the
commit shown in [1].

Regenerate etree.c with the matching Cython 3.0.9 release.  Keep the
iterparse source layout line-stable so that the generated diff contains
only the functional and documentation changes instead of unrelated
source-location updates.

[1] https://github.com/lxml/lxml/commit/ab431ea0b9a7357d968f1d1c5c614649e9aaf358
[2] https://github.com/lxml/lxml/security/advisories/GHSA-vfmq-68hx-4jfw

Signed-off-by: Darsh Kelaiya <[email protected]>
Signed-off-by: Yoann Congal <[email protected]>
---
 .../python/python3-lxml/CVE-2026-41066.patch  | 262 ++++++++++++++++++
 .../python/python3-lxml_5.0.2.bb              |   4 +-
 2 files changed, 265 insertions(+), 1 deletion(-)
 create mode 100644 
meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch

diff --git a/meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch 
b/meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch
new file mode 100644
index 00000000000..a58a0734723
--- /dev/null
+++ b/meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch
@@ -0,0 +1,262 @@
+From 4fe0735416504223919151aa43c8ccba4626597f Mon Sep 17 00:00:00 2001
+From: Stefan Behnel <[email protected]>
+Date: Fri, 10 Apr 2026 10:13:03 +0200
+Subject: [PATCH] LP#2146291: Set "resolve_entities='internal'" as default for
+ all parser subclasses.
+
+CVE: CVE-2026-41066
+Upstream-Status: Backport 
[https://github.com/lxml/lxml/commit/ab431ea0b9a7357d968f1d1c5c614649e9aaf358]
+
+Backport Changes:
+- Keep the lxml 5.0.2 XMLParser signature without decompress.
+- Keep the iterparse documentation and signature changes on existing
+  source lines, avoiding unrelated Cython source-location changes in
+  etree.c.
+- Regenerate src/lxml/etree.c with Cython 3.0.9 using Python 3.12:
+  python3.12 setup.py build_ext -i --with-cython --warnings -j1.
+  The command was run from an otherwise clean lxml 5.0.2 source tree
+  after applying the .pxi changes; the generated C file is retained
+  because the Scarthgap recipe does not depend on Cython at build time.
+
+(cherry picked from commit ab431ea0b9a7357d968f1d1c5c614649e9aaf358)
+Signed-off-by: Darsh Kelaiya <[email protected]>
+---
+ src/lxml/etree.c       | 40 ++++++++++++++++++++--------------------
+ src/lxml/iterparse.pxi |  6 +++---
+ src/lxml/parser.pxi    |  6 +++---
+ 3 files changed, 26 insertions(+), 26 deletions(-)
+
+diff --git a/src/lxml/etree.c b/src/lxml/etree.c
+index 6012a1b..41b3c45 100644
+--- a/src/lxml/etree.c
++++ b/src/lxml/etree.c
+@@ -3146,7 +3146,7 @@ struct __pyx_obj_4lxml_5etree__FeedParser {
+  *     )
+  * 
+  * cdef class XMLParser(_FeedParser):             # <<<<<<<<<<<<<<
+- *     u"""XMLParser(self, encoding=None, attribute_defaults=False, 
dtd_validation=False, load_dtd=False, no_network=True, ns_clean=False, 
recover=False, schema: XMLSchema =None, huge_tree=False, 
remove_blank_text=False, resolve_entities=True, remove_comments=False, 
remove_pis=False, strip_cdata=True, collect_ids=True, target=None, compact=True)
++ *     u"""XMLParser(self, encoding=None, attribute_defaults=False, 
dtd_validation=False, load_dtd=False, no_network=True, ns_clean=False, 
recover=False, schema: XMLSchema =None, huge_tree=False, 
remove_blank_text=False, resolve_entities='internal', remove_comments=False, 
remove_pis=False, strip_cdata=True, collect_ids=True, target=None, compact=True)
+  * 
+  */
+ struct __pyx_obj_4lxml_5etree_XMLParser {
+@@ -5424,7 +5424,7 @@ static struct __pyx_vtabstruct_4lxml_5etree__FeedParser 
*__pyx_vtabptr_4lxml_5et
+  *     )
+  * 
+  * cdef class XMLParser(_FeedParser):             # <<<<<<<<<<<<<<
+- *     u"""XMLParser(self, encoding=None, attribute_defaults=False, 
dtd_validation=False, load_dtd=False, no_network=True, ns_clean=False, 
recover=False, schema: XMLSchema =None, huge_tree=False, 
remove_blank_text=False, resolve_entities=True, remove_comments=False, 
remove_pis=False, strip_cdata=True, collect_ids=True, target=None, compact=True)
++ *     u"""XMLParser(self, encoding=None, attribute_defaults=False, 
dtd_validation=False, load_dtd=False, no_network=True, ns_clean=False, 
recover=False, schema: XMLSchema =None, huge_tree=False, 
remove_blank_text=False, resolve_entities='internal', remove_comments=False, 
remove_pis=False, strip_cdata=True, collect_ids=True, target=None, compact=True)
+  * 
+  */
+ 
+@@ -142620,7 +142620,7 @@ static int 
__pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v
+  *     def __init__(self, *, encoding=None, attribute_defaults=False,
+  *                  dtd_validation=False, load_dtd=False, no_network=True,    
         # <<<<<<<<<<<<<<
+  *                  ns_clean=False, recover=False, schema=None,
+- *                  huge_tree=False, remove_blank_text=False, 
resolve_entities=True,
++ *                  huge_tree=False, remove_blank_text=False, 
resolve_entities='internal',
+  */
+     values[2] = __Pyx_Arg_NewRef_VARARGS(((PyObject *)Py_False));
+     values[3] = __Pyx_Arg_NewRef_VARARGS(((PyObject *)Py_False));
+@@ -142630,7 +142630,7 @@ static int 
__pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v
+  *     def __init__(self, *, encoding=None, attribute_defaults=False,
+  *                  dtd_validation=False, load_dtd=False, no_network=True,
+  *                  ns_clean=False, recover=False, schema=None,             # 
<<<<<<<<<<<<<<
+- *                  huge_tree=False, remove_blank_text=False, 
resolve_entities=True,
++ *                  huge_tree=False, remove_blank_text=False, 
resolve_entities='internal',
+  *                  remove_comments=True, remove_pis=True, strip_cdata=True,
+  */
+     values[5] = __Pyx_Arg_NewRef_VARARGS(((PyObject *)Py_False));
+@@ -142640,17 +142640,17 @@ static int 
__pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v
+     /* "src/lxml/parser.pxi":1703
+  *                  dtd_validation=False, load_dtd=False, no_network=True,
+  *                  ns_clean=False, recover=False, schema=None,
+- *                  huge_tree=False, remove_blank_text=False, 
resolve_entities=True,             # <<<<<<<<<<<<<<
++ *                  huge_tree=False, remove_blank_text=False, 
resolve_entities='internal',             # <<<<<<<<<<<<<<
+  *                  remove_comments=True, remove_pis=True, strip_cdata=True,
+  *                  target=None, compact=True):
+  */
+     values[8] = __Pyx_Arg_NewRef_VARARGS(((PyObject *)Py_False));
+     values[9] = __Pyx_Arg_NewRef_VARARGS(((PyObject *)Py_False));
+-    values[10] = __Pyx_Arg_NewRef_VARARGS(((PyObject *)Py_True));
++    values[10] = __Pyx_Arg_NewRef_VARARGS(((PyObject *)__pyx_n_s_internal));
+ 
+     /* "src/lxml/parser.pxi":1704
+  *                  ns_clean=False, recover=False, schema=None,
+- *                  huge_tree=False, remove_blank_text=False, 
resolve_entities=True,
++ *                  huge_tree=False, remove_blank_text=False, 
resolve_entities='internal',
+  *                  remove_comments=True, remove_pis=True, strip_cdata=True,  
           # <<<<<<<<<<<<<<
+  *                  target=None, compact=True):
+  *         XMLParser.__init__(self,
+@@ -142660,7 +142660,7 @@ static int 
__pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v
+     values[13] = __Pyx_Arg_NewRef_VARARGS(((PyObject *)Py_True));
+ 
+     /* "src/lxml/parser.pxi":1705
+- *                  huge_tree=False, remove_blank_text=False, 
resolve_entities=True,
++ *                  huge_tree=False, remove_blank_text=False, 
resolve_entities='internal',
+  *                  remove_comments=True, remove_pis=True, strip_cdata=True,
+  *                  target=None, compact=True):             # <<<<<<<<<<<<<<
+  *         XMLParser.__init__(self,
+@@ -191418,7 +191418,7 @@ static int 
__pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py
+  *     def __init__(self, source, events=(u"end",), *, tag=None,
+  *                  attribute_defaults=False, dtd_validation=False,           
  # <<<<<<<<<<<<<<
+  *                  load_dtd=False, no_network=True, remove_blank_text=False,
+- *                  compact=True, resolve_entities=True, 
remove_comments=False,
++ *                  compact=True, resolve_entities='internal', 
remove_comments=False,
+  */
+     values[3] = __Pyx_Arg_NewRef_VARARGS(((PyObject *)Py_False));
+     values[4] = __Pyx_Arg_NewRef_VARARGS(((PyObject *)Py_False));
+@@ -191427,7 +191427,7 @@ static int 
__pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py
+  *     def __init__(self, source, events=(u"end",), *, tag=None,
+  *                  attribute_defaults=False, dtd_validation=False,
+  *                  load_dtd=False, no_network=True, remove_blank_text=False, 
            # <<<<<<<<<<<<<<
+- *                  compact=True, resolve_entities=True, 
remove_comments=False,
++ *                  compact=True, resolve_entities='internal', 
remove_comments=False,
+  *                  remove_pis=False, strip_cdata=True, encoding=None,
+  */
+     values[5] = __Pyx_Arg_NewRef_VARARGS(((PyObject *)Py_False));
+@@ -191437,17 +191437,17 @@ static int 
__pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py
+     /* "src/lxml/iterparse.pxi":70
+  *                  attribute_defaults=False, dtd_validation=False,
+  *                  load_dtd=False, no_network=True, remove_blank_text=False,
+- *                  compact=True, resolve_entities=True, 
remove_comments=False,             # <<<<<<<<<<<<<<
++ *                  compact=True, resolve_entities='internal', 
remove_comments=False,             # <<<<<<<<<<<<<<
+  *                  remove_pis=False, strip_cdata=True, encoding=None,
+  *                  html=False, recover=None, huge_tree=False, 
collect_ids=True,
+  */
+     values[8] = __Pyx_Arg_NewRef_VARARGS(((PyObject *)Py_True));
+-    values[9] = __Pyx_Arg_NewRef_VARARGS(((PyObject *)Py_True));
++    values[9] = __Pyx_Arg_NewRef_VARARGS(((PyObject *)__pyx_n_s_internal));
+     values[10] = __Pyx_Arg_NewRef_VARARGS(((PyObject *)Py_False));
+ 
+     /* "src/lxml/iterparse.pxi":71
+  *                  load_dtd=False, no_network=True, remove_blank_text=False,
+- *                  compact=True, resolve_entities=True, 
remove_comments=False,
++ *                  compact=True, resolve_entities='internal', 
remove_comments=False,
+  *                  remove_pis=False, strip_cdata=True, encoding=None,        
     # <<<<<<<<<<<<<<
+  *                  html=False, recover=None, huge_tree=False, 
collect_ids=True,
+  *                  XMLSchema schema=None):
+@@ -191457,7 +191457,7 @@ static int 
__pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py
+     values[13] = __Pyx_Arg_NewRef_VARARGS(((PyObject *)Py_None));
+ 
+     /* "src/lxml/iterparse.pxi":72
+- *                  compact=True, resolve_entities=True, 
remove_comments=False,
++ *                  compact=True, resolve_entities='internal', 
remove_comments=False,
+  *                  remove_pis=False, strip_cdata=True, encoding=None,
+  *                  html=False, recover=None, huge_tree=False, 
collect_ids=True,             # <<<<<<<<<<<<<<
+  *                  XMLSchema schema=None):
+@@ -263534,7 +263534,7 @@ static PyMethodDef 
__pyx_methods_4lxml_5etree_XMLParser[] = {
+ };
+ #if CYTHON_USE_TYPE_SPECS
+ static PyType_Slot __pyx_type_4lxml_5etree_XMLParser_slots[] = {
+-  {Py_tp_doc, (void *)PyDoc_STR("XMLParser(self, encoding=None, 
attribute_defaults=False, dtd_validation=False, load_dtd=False, 
no_network=True, ns_clean=False, recover=False, schema: XMLSchema =None, 
huge_tree=False, remove_blank_text=False, resolve_entities=True, 
remove_comments=False, remove_pis=False, strip_cdata=True, collect_ids=True, 
target=None, compact=True)\n\n    The XML parser.\n\n    Parsers can be 
supplied as additional argument to various parse\n    functions of the lxml 
API.  A default parser is always available\n    and can be replaced by a call 
to the global function\n    'set_default_parser'.  New parsers can be created 
at any time\n    without a major run-time overhead.\n\n    The keyword 
arguments in the constructor are mainly based on the\n    libxml2 parser 
configuration.  A DTD will also be loaded if DTD\n    validation or attribute 
default values are requested (unless you\n    additionally provide an XMLSchema 
from which the default\n    attributes can be read).\n\n    Available boolean 
keyword arguments:\n\n    - attribute_defaults - inject default attributes from 
DTD or XMLSchema\n    - dtd_validation     - validate against a DTD referenced 
by the document\n    - load_dtd           - use DTD for parsing\n    - 
no_network         - prevent network access for related files (default: True)\n 
   - ns_clean           - clean up redundant namespace declarations\n    - 
recover            - try hard to parse through broken XML\n    - 
remove_blank_text  - discard blank text nodes that appear ignorable\n    - 
remove_comments    - discard comments\n    - remove_pis         - discard 
processing instructions\n    - strip_cdata        - replace CDATA sections by 
normal text content (default: True)\n    - compact            - save memory for 
short text content (default: True)\n    - collect_ids        - use a hash table 
of XML IDs for fast access (default: True, always True with DTD validation)\n   
 - huge_tree          - disable security restrictions and support very deep 
trees\n      ""                     and very long text content (only affects 
libxml2 2.7+)\n\n    Other keyword arguments:\n\n    - resolve_entities - 
replace entities by their text value: False for keeping the\n          entity 
references, True for resolving them, and 'internal' for resolving\n          
internal definitions only (no external file/URL access).\n          The default 
used to be True and was changed to 'internal' in lxml 5.0.\n    - encoding - 
override the document encoding (note: libiconv encoding name)\n    - target   - 
a parser target object that will receive the parse events\n    - schema   - an 
XMLSchema to validate against\n\n    Note that you should avoid sharing parsers 
between threads.  While this is\n    not harmful, it is more efficient to use 
separate parsers.  This does not\n    apply to the default parser.\n    ")},
++  {Py_tp_doc, (void *)PyDoc_STR("XMLParser(self, encoding=None, 
attribute_defaults=False, dtd_validation=False, load_dtd=False, 
no_network=True, ns_clean=False, recover=False, schema: XMLSchema =None, 
huge_tree=False, remove_blank_text=False, resolve_entities='internal', 
remove_comments=False, remove_pis=False, strip_cdata=True, collect_ids=True, 
target=None, compact=True)\n\n    The XML parser.\n\n    Parsers can be 
supplied as additional argument to various parse\n    functions of the lxml 
API.  A default parser is always available\n    and can be replaced by a call 
to the global function\n    'set_default_parser'.  New parsers can be created 
at any time\n    without a major run-time overhead.\n\n    The keyword 
arguments in the constructor are mainly based on the\n    libxml2 parser 
configuration.  A DTD will also be loaded if DTD\n    validation or attribute 
default values are requested (unless you\n    additionally provide an XMLSchema 
from which the default\n    attributes can be read).\n\n    Available boolean 
keyword arguments:\n\n    - attribute_defaults - inject default attributes from 
DTD or XMLSchema\n    - dtd_validation     - validate against a DTD referenced 
by the document\n    - load_dtd           - use DTD for parsing\n    - 
no_network         - prevent network access for related files (default: True)\n 
   - ns_clean           - clean up redundant namespace declarations\n    - 
recover            - try hard to parse through broken XML\n    - 
remove_blank_text  - discard blank text nodes that appear ignorable\n    - 
remove_comments    - discard comments\n    - remove_pis         - discard 
processing instructions\n    - strip_cdata        - replace CDATA sections by 
normal text content (default: True)\n    - compact            - save memory for 
short text content (default: True)\n    - collect_ids        - use a hash table 
of XML IDs for fast access (default: True, always True with DTD validation)\n   
 - huge_tree          - disable security restrictions and support very deep 
trees""\n                           and very long text content (only affects 
libxml2 2.7+)\n\n    Other keyword arguments:\n\n    - resolve_entities - 
replace entities by their text value: False for keeping the\n          entity 
references, True for resolving them, and 'internal' for resolving\n          
internal definitions only (no external file/URL access).\n          The default 
used to be True and was changed to 'internal' in lxml 5.0.\n    - encoding - 
override the document encoding (note: libiconv encoding name)\n    - target   - 
a parser target object that will receive the parse events\n    - schema   - an 
XMLSchema to validate against\n\n    Note that you should avoid sharing parsers 
between threads.  While this is\n    not harmful, it is more efficient to use 
separate parsers.  This does not\n    apply to the default parser.\n    ")},
+   {Py_tp_traverse, (void *)__pyx_tp_traverse_4lxml_5etree__BaseParser},
+   {Py_tp_clear, (void *)__pyx_tp_clear_4lxml_5etree__BaseParser},
+   {Py_tp_methods, (void *)__pyx_methods_4lxml_5etree_XMLParser},
+@@ -263582,7 +263582,7 @@ static PyTypeObject 
__pyx_type_4lxml_5etree_XMLParser = {
+   0, /*tp_setattro*/
+   0, /*tp_as_buffer*/
+   
Py_TPFLAGS_DEFAULT|Py_TPFLAGS_HAVE_VERSION_TAG|Py_TPFLAGS_CHECKTYPES|Py_TPFLAGS_HAVE_NEWBUFFER|Py_TPFLAGS_BASETYPE|Py_TPFLAGS_HAVE_GC,
 /*tp_flags*/
+-  PyDoc_STR("XMLParser(self, encoding=None, attribute_defaults=False, 
dtd_validation=False, load_dtd=False, no_network=True, ns_clean=False, 
recover=False, schema: XMLSchema =None, huge_tree=False, 
remove_blank_text=False, resolve_entities=True, remove_comments=False, 
remove_pis=False, strip_cdata=True, collect_ids=True, target=None, 
compact=True)\n\n    The XML parser.\n\n    Parsers can be supplied as 
additional argument to various parse\n    functions of the lxml API.  A default 
parser is always available\n    and can be replaced by a call to the global 
function\n    'set_default_parser'.  New parsers can be created at any time\n   
 without a major run-time overhead.\n\n    The keyword arguments in the 
constructor are mainly based on the\n    libxml2 parser configuration.  A DTD 
will also be loaded if DTD\n    validation or attribute default values are 
requested (unless you\n    additionally provide an XMLSchema from which the 
default\n    attributes can be read).\n\n    Available boolean keyword 
arguments:\n\n    - attribute_defaults - inject default attributes from DTD or 
XMLSchema\n    - dtd_validation     - validate against a DTD referenced by the 
document\n    - load_dtd           - use DTD for parsing\n    - no_network      
   - prevent network access for related files (default: True)\n    - ns_clean   
        - clean up redundant namespace declarations\n    - recover            - 
try hard to parse through broken XML\n    - remove_blank_text  - discard blank 
text nodes that appear ignorable\n    - remove_comments    - discard comments\n 
   - remove_pis         - discard processing instructions\n    - strip_cdata    
    - replace CDATA sections by normal text content (default: True)\n    - 
compact            - save memory for short text content (default: True)\n    - 
collect_ids        - use a hash table of XML IDs for fast access (default: 
True, always True with DTD validation)\n    - huge_tree          - disable 
security restrictions and support very deep trees\n      ""                     
and very long text content (only affects libxml2 2.7+)\n\n    Other keyword 
arguments:\n\n    - resolve_entities - replace entities by their text value: 
False for keeping the\n          entity references, True for resolving them, 
and 'internal' for resolving\n          internal definitions only (no external 
file/URL access).\n          The default used to be True and was changed to 
'internal' in lxml 5.0.\n    - encoding - override the document encoding (note: 
libiconv encoding name)\n    - target   - a parser target object that will 
receive the parse events\n    - schema   - an XMLSchema to validate against\n\n 
   Note that you should avoid sharing parsers between threads.  While this is\n 
   not harmful, it is more efficient to use separate parsers.  This does not\n  
  apply to the default parser.\n    "), /*tp_doc*/
++  PyDoc_STR("XMLParser(self, encoding=None, attribute_defaults=False, 
dtd_validation=False, load_dtd=False, no_network=True, ns_clean=False, 
recover=False, schema: XMLSchema =None, huge_tree=False, 
remove_blank_text=False, resolve_entities='internal', remove_comments=False, 
remove_pis=False, strip_cdata=True, collect_ids=True, target=None, 
compact=True)\n\n    The XML parser.\n\n    Parsers can be supplied as 
additional argument to various parse\n    functions of the lxml API.  A default 
parser is always available\n    and can be replaced by a call to the global 
function\n    'set_default_parser'.  New parsers can be created at any time\n   
 without a major run-time overhead.\n\n    The keyword arguments in the 
constructor are mainly based on the\n    libxml2 parser configuration.  A DTD 
will also be loaded if DTD\n    validation or attribute default values are 
requested (unless you\n    additionally provide an XMLSchema from which the 
default\n    attributes can be read).\n\n    Available boolean keyword 
arguments:\n\n    - attribute_defaults - inject default attributes from DTD or 
XMLSchema\n    - dtd_validation     - validate against a DTD referenced by the 
document\n    - load_dtd           - use DTD for parsing\n    - no_network      
   - prevent network access for related files (default: True)\n    - ns_clean   
        - clean up redundant namespace declarations\n    - recover            - 
try hard to parse through broken XML\n    - remove_blank_text  - discard blank 
text nodes that appear ignorable\n    - remove_comments    - discard comments\n 
   - remove_pis         - discard processing instructions\n    - strip_cdata    
    - replace CDATA sections by normal text content (default: True)\n    - 
compact            - save memory for short text content (default: True)\n    - 
collect_ids        - use a hash table of XML IDs for fast access (default: 
True, always True with DTD validation)\n    - huge_tree          - disable 
security restrictions and support very deep trees""\n                           
and very long text content (only affects libxml2 2.7+)\n\n    Other keyword 
arguments:\n\n    - resolve_entities - replace entities by their text value: 
False for keeping the\n          entity references, True for resolving them, 
and 'internal' for resolving\n          internal definitions only (no external 
file/URL access).\n          The default used to be True and was changed to 
'internal' in lxml 5.0.\n    - encoding - override the document encoding (note: 
libiconv encoding name)\n    - target   - a parser target object that will 
receive the parse events\n    - schema   - an XMLSchema to validate against\n\n 
   Note that you should avoid sharing parsers between threads.  While this is\n 
   not harmful, it is more efficient to use separate parsers.  This does not\n  
  apply to the default parser.\n    "), /*tp_doc*/
+   __pyx_tp_traverse_4lxml_5etree__BaseParser, /*tp_traverse*/
+   __pyx_tp_clear_4lxml_5etree__BaseParser, /*tp_clear*/
+   0, /*tp_richcompare*/
+@@ -263763,7 +263763,7 @@ static PyMethodDef 
__pyx_methods_4lxml_5etree_ETCompatXMLParser[] = {
+ };
+ #if CYTHON_USE_TYPE_SPECS
+ static PyType_Slot __pyx_type_4lxml_5etree_ETCompatXMLParser_slots[] = {
+-  {Py_tp_doc, (void *)PyDoc_STR("ETCompatXMLParser(self, encoding=None, 
attribute_defaults=False,                  dtd_validation=False, 
load_dtd=False, no_network=True,                  ns_clean=False, 
recover=False, schema=None,                  huge_tree=False, 
remove_blank_text=False, resolve_entities=True,                  
remove_comments=True, remove_pis=True, strip_cdata=True,                  
target=None, compact=True)\n\n    An XML parser with an ElementTree compatible 
default setup.\n\n    See the XMLParser class for details.\n\n    This parser 
has ``remove_comments`` and ``remove_pis`` enabled by default\n    and thus 
ignores comments and processing instructions.\n    ")},
++  {Py_tp_doc, (void *)PyDoc_STR("ETCompatXMLParser(self, encoding=None, 
attribute_defaults=False,                  dtd_validation=False, 
load_dtd=False, no_network=True,                  ns_clean=False, 
recover=False, schema=None,                  huge_tree=False, 
remove_blank_text=False, resolve_entities='internal',                  
remove_comments=True, remove_pis=True, strip_cdata=True,                  
target=None, compact=True)\n\n    An XML parser with an ElementTree compatible 
default setup.\n\n    See the XMLParser class for details.\n\n    This parser 
has ``remove_comments`` and ``remove_pis`` enabled by default\n    and thus 
ignores comments and processing instructions.\n    ")},
+   {Py_tp_traverse, (void *)__pyx_tp_traverse_4lxml_5etree__BaseParser},
+   {Py_tp_clear, (void *)__pyx_tp_clear_4lxml_5etree__BaseParser},
+   {Py_tp_methods, (void *)__pyx_methods_4lxml_5etree_ETCompatXMLParser},
+@@ -263811,7 +263811,7 @@ static PyTypeObject 
__pyx_type_4lxml_5etree_ETCompatXMLParser = {
+   0, /*tp_setattro*/
+   0, /*tp_as_buffer*/
+   
Py_TPFLAGS_DEFAULT|Py_TPFLAGS_HAVE_VERSION_TAG|Py_TPFLAGS_CHECKTYPES|Py_TPFLAGS_HAVE_NEWBUFFER|Py_TPFLAGS_BASETYPE|Py_TPFLAGS_HAVE_GC,
 /*tp_flags*/
+-  PyDoc_STR("ETCompatXMLParser(self, encoding=None, attribute_defaults=False, 
                 dtd_validation=False, load_dtd=False, no_network=True,         
         ns_clean=False, recover=False, schema=None,                  
huge_tree=False, remove_blank_text=False, resolve_entities=True,                
  remove_comments=True, remove_pis=True, strip_cdata=True,                  
target=None, compact=True)\n\n    An XML parser with an ElementTree compatible 
default setup.\n\n    See the XMLParser class for details.\n\n    This parser 
has ``remove_comments`` and ``remove_pis`` enabled by default\n    and thus 
ignores comments and processing instructions.\n    "), /*tp_doc*/
++  PyDoc_STR("ETCompatXMLParser(self, encoding=None, attribute_defaults=False, 
                 dtd_validation=False, load_dtd=False, no_network=True,         
         ns_clean=False, recover=False, schema=None,                  
huge_tree=False, remove_blank_text=False, resolve_entities='internal',          
        remove_comments=True, remove_pis=True, strip_cdata=True,                
  target=None, compact=True)\n\n    An XML parser with an ElementTree 
compatible default setup.\n\n    See the XMLParser class for details.\n\n    
This parser has ``remove_comments`` and ``remove_pis`` enabled by default\n    
and thus ignores comments and processing instructions.\n    "), /*tp_doc*/
+   __pyx_tp_traverse_4lxml_5etree__BaseParser, /*tp_traverse*/
+   __pyx_tp_clear_4lxml_5etree__BaseParser, /*tp_clear*/
+   0, /*tp_richcompare*/
+@@ -267005,7 +267005,7 @@ static struct PyGetSetDef 
__pyx_getsets_4lxml_5etree_iterparse[] = {
+ #if CYTHON_USE_TYPE_SPECS
+ static PyType_Slot __pyx_type_4lxml_5etree_iterparse_slots[] = {
+   {Py_tp_dealloc, (void *)__pyx_tp_dealloc_4lxml_5etree_iterparse},
+-  {Py_tp_doc, (void *)PyDoc_STR("iterparse(self, source, events=(\"end\",), 
tag=None,                   attribute_defaults=False, dtd_validation=False,     
              load_dtd=False, no_network=True, remove_blank_text=False,         
          remove_comments=False, remove_pis=False, encoding=None,               
    html=False, recover=None, huge_tree=False, schema=None)\n\n    Incremental 
parser.\n\n    Parses XML into a tree and generates tuples (event, element) in 
a\n    SAX-like fashion. ``event`` is any of 'start', 'end', 'start-ns',\n    
'end-ns'.\n\n    For 'start' and 'end', ``element`` is the Element that the 
parser just\n    found opening or closing.  For 'start-ns', it is a tuple 
(prefix, URI) of\n    a new namespace declaration.  For 'end-ns', it is simply 
None.  Note that\n    all start and end events are guaranteed to be properly 
nested.\n\n    The keyword argument ``events`` specifies a sequence of event 
type names\n    that should be generated.  By default, only 'end' events will 
be\n    generated.\n\n    The additional ``tag`` argument restricts the 'start' 
and 'end' events to\n    those elements that match the given tag.  The ``tag`` 
argument can also be\n    a sequence of tags to allow matching more than one 
tag.  By default,\n    events are generated for all elements.  Note that the 
'start-ns' and\n    'end-ns' events are not impacted by this restriction.\n\n   
 The other keyword arguments in the constructor are mainly based on the\n    
libxml2 parser configuration.  A DTD will also be loaded if validation or\n    
attribute default values are requested.\n\n    Available boolean keyword 
arguments:\n     - attribute_defaults: read default attributes from DTD\n     - 
dtd_validation: validate (if DTD is available)\n     - load_dtd: use DTD for 
parsing\n     - no_network: prevent network access for related files\n     - 
remove_blank_text: discard blank text nodes\n     - remove_comments: discard 
comments\n     - remove_pis: discard processing instructions\n     - 
strip_cdata: repla""ce CDATA sections by normal text content (default: True)\n  
   - compact: safe memory for short text content (default: True)\n     - 
resolve_entities: replace entities by their text value (default: True)\n     - 
huge_tree: disable security restrictions and support very deep trees\n          
        and very long text content (only affects libxml2 2.7+)\n     - html: 
parse input as HTML (default: XML)\n     - recover: try hard to parse through 
broken input (default: True for HTML,\n                False otherwise)\n\n    
Other keyword arguments:\n     - encoding: override the document encoding\n     
- schema: an XMLSchema to validate against\n    ")},
++  {Py_tp_doc, (void *)PyDoc_STR("iterparse(self, source, events=(\"end\",), 
tag=None,                   attribute_defaults=False, dtd_validation=False,     
              load_dtd=False, no_network=True, remove_blank_text=False,         
          compact=True, resolve_entities='internal', remove_comments=False, 
remove_pis=False, strip_cdata=True, encoding=None,                   
html=False, recover=None, huge_tree=False, schema=None)\n\n    Incremental 
parser.\n\n    Parses XML into a tree and generates tuples (event, element) in 
a\n    SAX-like fashion. ``event`` is any of 'start', 'end', 'start-ns',\n    
'end-ns'.\n\n    For 'start' and 'end', ``element`` is the Element that the 
parser just\n    found opening or closing.  For 'start-ns', it is a tuple 
(prefix, URI) of\n    a new namespace declaration.  For 'end-ns', it is simply 
None.  Note that\n    all start and end events are guaranteed to be properly 
nested.\n\n    The keyword argument ``events`` specifies a sequence of event 
type names\n    that should be generated.  By default, only 'end' events will 
be\n    generated.\n\n    The additional ``tag`` argument restricts the 'start' 
and 'end' events to\n    those elements that match the given tag.  The ``tag`` 
argument can also be\n    a sequence of tags to allow matching more than one 
tag.  By default,\n    events are generated for all elements.  Note that the 
'start-ns' and\n    'end-ns' events are not impacted by this restriction.\n\n   
 The other keyword arguments in the constructor are mainly based on the\n    
libxml2 parser configuration.  A DTD will also be loaded if validation or\n    
attribute default values are requested.\n\n    Available boolean keyword 
arguments:\n     - attribute_defaults: read default attributes from DTD\n     - 
dtd_validation: validate (if DTD is available)\n     - load_dtd: use DTD for 
parsing\n     - no_network: prevent network access for related files\n     - 
remove_blank_text: discard blank text nodes\n     - remove_comments: discard 
comments\n     - remove_pi""s: discard processing instructions\n     - 
strip_cdata: replace CDATA sections by normal text content (default: True)\n    
 - compact: safe memory for short text content (default: True)\n     - 
resolve_entities: replace entities by their text value (default: 'internal' 
only)\n     - huge_tree: disable security restrictions and support very deep 
trees\n                  and very long text content (only affects libxml2 
2.7+)\n     - html: parse input as HTML (default: XML)\n     - recover: try 
hard to parse through broken input (default: True for HTML,\n                
False otherwise)\n\n    Other keyword arguments:\n     - encoding: override the 
document encoding\n     - schema: an XMLSchema to validate against\n    ")},
+   {Py_tp_traverse, (void *)__pyx_tp_traverse_4lxml_5etree_iterparse},
+   {Py_tp_clear, (void *)__pyx_tp_clear_4lxml_5etree_iterparse},
+   {Py_tp_iter, (void *)__pyx_pw_4lxml_5etree_9iterparse_7__iter__},
+@@ -267056,7 +267056,7 @@ static PyTypeObject 
__pyx_type_4lxml_5etree_iterparse = {
+   0, /*tp_setattro*/
+   0, /*tp_as_buffer*/
+   
Py_TPFLAGS_DEFAULT|Py_TPFLAGS_HAVE_VERSION_TAG|Py_TPFLAGS_CHECKTYPES|Py_TPFLAGS_HAVE_NEWBUFFER|Py_TPFLAGS_BASETYPE|Py_TPFLAGS_HAVE_GC,
 /*tp_flags*/
+-  PyDoc_STR("iterparse(self, source, events=(\"end\",), tag=None,             
      attribute_defaults=False, dtd_validation=False,                   
load_dtd=False, no_network=True, remove_blank_text=False,                   
remove_comments=False, remove_pis=False, encoding=None,                   
html=False, recover=None, huge_tree=False, schema=None)\n\n    Incremental 
parser.\n\n    Parses XML into a tree and generates tuples (event, element) in 
a\n    SAX-like fashion. ``event`` is any of 'start', 'end', 'start-ns',\n    
'end-ns'.\n\n    For 'start' and 'end', ``element`` is the Element that the 
parser just\n    found opening or closing.  For 'start-ns', it is a tuple 
(prefix, URI) of\n    a new namespace declaration.  For 'end-ns', it is simply 
None.  Note that\n    all start and end events are guaranteed to be properly 
nested.\n\n    The keyword argument ``events`` specifies a sequence of event 
type names\n    that should be generated.  By default, only 'end' events will 
be\n    generated.\n\n    The additional ``tag`` argument restricts the 'start' 
and 'end' events to\n    those elements that match the given tag.  The ``tag`` 
argument can also be\n    a sequence of tags to allow matching more than one 
tag.  By default,\n    events are generated for all elements.  Note that the 
'start-ns' and\n    'end-ns' events are not impacted by this restriction.\n\n   
 The other keyword arguments in the constructor are mainly based on the\n    
libxml2 parser configuration.  A DTD will also be loaded if validation or\n    
attribute default values are requested.\n\n    Available boolean keyword 
arguments:\n     - attribute_defaults: read default attributes from DTD\n     - 
dtd_validation: validate (if DTD is available)\n     - load_dtd: use DTD for 
parsing\n     - no_network: prevent network access for related files\n     - 
remove_blank_text: discard blank text nodes\n     - remove_comments: discard 
comments\n     - remove_pis: discard processing instructions\n     - 
strip_cdata: repla""ce CDATA sections by normal text content (default: True)\n  
   - compact: safe memory for short text content (default: True)\n     - 
resolve_entities: replace entities by their text value (default: True)\n     - 
huge_tree: disable security restrictions and support very deep trees\n          
        and very long text content (only affects libxml2 2.7+)\n     - html: 
parse input as HTML (default: XML)\n     - recover: try hard to parse through 
broken input (default: True for HTML,\n                False otherwise)\n\n    
Other keyword arguments:\n     - encoding: override the document encoding\n     
- schema: an XMLSchema to validate against\n    "), /*tp_doc*/
++  PyDoc_STR("iterparse(self, source, events=(\"end\",), tag=None,             
      attribute_defaults=False, dtd_validation=False,                   
load_dtd=False, no_network=True, remove_blank_text=False,                   
compact=True, resolve_entities='internal', remove_comments=False, 
remove_pis=False, strip_cdata=True, encoding=None,                   
html=False, recover=None, huge_tree=False, schema=None)\n\n    Incremental 
parser.\n\n    Parses XML into a tree and generates tuples (event, element) in 
a\n    SAX-like fashion. ``event`` is any of 'start', 'end', 'start-ns',\n    
'end-ns'.\n\n    For 'start' and 'end', ``element`` is the Element that the 
parser just\n    found opening or closing.  For 'start-ns', it is a tuple 
(prefix, URI) of\n    a new namespace declaration.  For 'end-ns', it is simply 
None.  Note that\n    all start and end events are guaranteed to be properly 
nested.\n\n    The keyword argument ``events`` specifies a sequence of event 
type names\n    that should be generated.  By default, only 'end' events will 
be\n    generated.\n\n    The additional ``tag`` argument restricts the 'start' 
and 'end' events to\n    those elements that match the given tag.  The ``tag`` 
argument can also be\n    a sequence of tags to allow matching more than one 
tag.  By default,\n    events are generated for all elements.  Note that the 
'start-ns' and\n    'end-ns' events are not impacted by this restriction.\n\n   
 The other keyword arguments in the constructor are mainly based on the\n    
libxml2 parser configuration.  A DTD will also be loaded if validation or\n    
attribute default values are requested.\n\n    Available boolean keyword 
arguments:\n     - attribute_defaults: read default attributes from DTD\n     - 
dtd_validation: validate (if DTD is available)\n     - load_dtd: use DTD for 
parsing\n     - no_network: prevent network access for related files\n     - 
remove_blank_text: discard blank text nodes\n     - remove_comments: discard 
comments\n     - remove_pi""s: discard processing instructions\n     - 
strip_cdata: replace CDATA sections by normal text content (default: True)\n    
 - compact: safe memory for short text content (default: True)\n     - 
resolve_entities: replace entities by their text value (default: 'internal' 
only)\n     - huge_tree: disable security restrictions and support very deep 
trees\n                  and very long text content (only affects libxml2 
2.7+)\n     - html: parse input as HTML (default: XML)\n     - recover: try 
hard to parse through broken input (default: True for HTML,\n                
False otherwise)\n\n    Other keyword arguments:\n     - encoding: override the 
document encoding\n     - schema: an XMLSchema to validate against\n    "), 
/*tp_doc*/
+   __pyx_tp_traverse_4lxml_5etree_iterparse, /*tp_traverse*/
+   __pyx_tp_clear_4lxml_5etree_iterparse, /*tp_clear*/
+   0, /*tp_richcompare*/
+diff --git a/src/lxml/iterparse.pxi b/src/lxml/iterparse.pxi
+index 2758b14..d8fc02f 100644
+--- a/src/lxml/iterparse.pxi
++++ b/src/lxml/iterparse.pxi
+@@ -6,7 +6,7 @@ cdef class iterparse:
+     u"""iterparse(self, source, events=("end",), tag=None, \
+                   attribute_defaults=False, dtd_validation=False, \
+                   load_dtd=False, no_network=True, remove_blank_text=False, \
+-                  remove_comments=False, remove_pis=False, encoding=None, \
++                  compact=True, resolve_entities='internal', 
remove_comments=False, remove_pis=False, strip_cdata=True, encoding=None, \
+                   html=False, recover=None, huge_tree=False, schema=None)
+ 
+     Incremental parser.
+@@ -44,7 +44,7 @@ cdef class iterparse:
+      - remove_pis: discard processing instructions
+      - strip_cdata: replace CDATA sections by normal text content (default: 
True)
+      - compact: safe memory for short text content (default: True)
+-     - resolve_entities: replace entities by their text value (default: True)
++     - resolve_entities: replace entities by their text value (default: 
'internal' only)
+      - huge_tree: disable security restrictions and support very deep trees
+                   and very long text content (only affects libxml2 2.7+)
+      - html: parse input as HTML (default: XML)
+@@ -67,7 +67,7 @@ cdef class iterparse:
+     def __init__(self, source, events=(u"end",), *, tag=None,
+                  attribute_defaults=False, dtd_validation=False,
+                  load_dtd=False, no_network=True, remove_blank_text=False,
+-                 compact=True, resolve_entities=True, remove_comments=False,
++                 compact=True, resolve_entities='internal', 
remove_comments=False,
+                  remove_pis=False, strip_cdata=True, encoding=None,
+                  html=False, recover=None, huge_tree=False, collect_ids=True,
+                  XMLSchema schema=None):
+diff --git a/src/lxml/parser.pxi b/src/lxml/parser.pxi
+index e9f4bec..bded239 100644
+--- a/src/lxml/parser.pxi
++++ b/src/lxml/parser.pxi
+@@ -1564,7 +1564,7 @@ _XML_DEFAULT_PARSE_OPTIONS = (
+     )
+ 
+ cdef class XMLParser(_FeedParser):
+-    u"""XMLParser(self, encoding=None, attribute_defaults=False, 
dtd_validation=False, load_dtd=False, no_network=True, ns_clean=False, 
recover=False, schema: XMLSchema =None, huge_tree=False, 
remove_blank_text=False, resolve_entities=True, remove_comments=False, 
remove_pis=False, strip_cdata=True, collect_ids=True, target=None, compact=True)
++    u"""XMLParser(self, encoding=None, attribute_defaults=False, 
dtd_validation=False, load_dtd=False, no_network=True, ns_clean=False, 
recover=False, schema: XMLSchema =None, huge_tree=False, 
remove_blank_text=False, resolve_entities='internal', remove_comments=False, 
remove_pis=False, strip_cdata=True, collect_ids=True, target=None, compact=True)
+ 
+     The XML parser.
+ 
+@@ -1686,7 +1686,7 @@ cdef class ETCompatXMLParser(XMLParser):
+     u"""ETCompatXMLParser(self, encoding=None, attribute_defaults=False, \
+                  dtd_validation=False, load_dtd=False, no_network=True, \
+                  ns_clean=False, recover=False, schema=None, \
+-                 huge_tree=False, remove_blank_text=False, 
resolve_entities=True, \
++                 huge_tree=False, remove_blank_text=False, 
resolve_entities='internal', \
+                  remove_comments=True, remove_pis=True, strip_cdata=True, \
+                  target=None, compact=True)
+ 
+@@ -1700,7 +1700,7 @@ cdef class ETCompatXMLParser(XMLParser):
+     def __init__(self, *, encoding=None, attribute_defaults=False,
+                  dtd_validation=False, load_dtd=False, no_network=True,
+                  ns_clean=False, recover=False, schema=None,
+-                 huge_tree=False, remove_blank_text=False, 
resolve_entities=True,
++                 huge_tree=False, remove_blank_text=False, 
resolve_entities='internal',
+                  remove_comments=True, remove_pis=True, strip_cdata=True,
+                  target=None, compact=True):
+         XMLParser.__init__(self,
diff --git a/meta/recipes-devtools/python/python3-lxml_5.0.2.bb 
b/meta/recipes-devtools/python/python3-lxml_5.0.2.bb
index c0b385c7ea8..2d2d55202c0 100644
--- a/meta/recipes-devtools/python/python3-lxml_5.0.2.bb
+++ b/meta/recipes-devtools/python/python3-lxml_5.0.2.bb
@@ -20,7 +20,9 @@ DEPENDS += "libxml2 libxslt"
 
 SRC_URI[sha256sum] = 
"6399703c40ba53e2c3b72fdb56cb908d2b83c08082ecf17de839b27e68d1e598"
 
-SRC_URI += "${PYPI_SRC_URI}"
+SRC_URI += "${PYPI_SRC_URI} \
+            file://CVE-2026-41066.patch \
+           "
 inherit pkgconfig pypi setuptools3
 
 # {standard input}: Assembler messages:
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#245680): 
https://lists.openembedded.org/g/openembedded-core/message/245680
Mute This Topic: https://lists.openembedded.org/mt/121207014/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to