CVE-2026-58501

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
08/07/2026
Last modified:
10/07/2026

Description

Zeep is a Python SOAP client. From 4.0.0 before 4.3.3, Settings.forbid_external is defined but not enforced when parsing WSDL or XSD documents, allowing transitive xsd:import, xsd:include, wsdl:import, and lxml entity or DTD references to fetch attacker-chosen HTTP or HTTPS URLs. This issue is fixed in version 4.3.3.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:python-zeep:zeep:*:*:*:*:*:python:*:* 4.0.0 (including) 4.3.3 (excluding)