CVE-2026-58501: Python-Zeep Zeep
Medium severity, CVSS 5.9. EPSS: 0.4% chance of exploitation in the next 30 days.
Zeep is a Python SOAP client. From 4.0.0 before 4.3.3, Settings.forbid_external is defined but not enforced when parsing WSDL or XSD documents, allowing transitive xsd:import, xsd:include, wsdl:import, and lxml entity or DTD references to fetch attacker-chosen HTTP or HTTPS URLs. This issue is fixed in version 4.3.3.
Affected products
- Python-Zeep Zeep: from 4.0.0, before 4.3.3 (fixed in 4.3.3)
Published 2026-07-08. Last modified 2026-07-10.