PatchSiren cyber security CVE debrief
CVE-2026-58501 mvantellingen CVE debrief
CVE-2026-58501 is a vulnerability in the Zeep Python SOAP client. Versions from 4.0.0 before 4.3.3 define but do not enforce the Settings.forbid_external setting when parsing WSDL or XSD documents. This oversight allows for transitive xsd:import, xsd:include, wsdl:import, and lxml entity or DTD references to fetch attacker-chosen HTTP or HTTPS URLs. The vulnerability has a CVSS score of 5.9 and is classified as MEDIUM severity. The issue is fixed in version 4.3.3. Users and administrators of affected versions should take immediate action to mitigate potential risks.
- Vendor
- mvantellingen
- Product
- python-zeep
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-08
- Original CVE updated
- 2026-07-10
- Advisory published
- 2026-07-08
- Advisory updated
- 2026-07-10
Who should care
Users of Zeep SOAP client versions 4.0.0 through 4.3.2 should be aware of this vulnerability and take steps to mitigate it. This includes operators, administrators, and security teams responsible for maintaining and securing systems that utilize the Zeep SOAP client. Affected organizations should review their deployments, assess potential exposure, and implement recommended mitigations or patches.
Technical summary
The Zeep Python SOAP client vulnerability, CVE-2026-58501, arises from the improper enforcement of the Settings.forbid_external setting. This setting is intended to prevent the fetching of external resources when parsing WSDL or XSD documents. However, in versions 4.0.0 through 4.3.2, this setting is defined but not enforced, allowing an attacker to potentially fetch malicious content from attacker-controlled URLs. The vulnerability can be exploited through transitive xsd:import, xsd:include, wsdl:import, and lxml entity or DTD references. The issue has been fixed in version 4.3.3, which properly enforces the Settings.forbid_external setting.
Defensive priority
Medium
Recommended defensive actions
- Update Zeep to version 4.3.3 or later
- Review and restrict external resource access in WSDL and XSD documents
- Monitor for suspicious activity related to SOAP client usage
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record was published on 2026-07-08T20:16:55.323Z and was last modified on 2026-07-10T17:20:58.133Z. The NVD entry is currently Analyzed. The Zeep Python SOAP client vulnerability, CVE-2026-58501, arises from the improper enforcement of the Settings.forbid_external setting. This setting is intended to prevent the fetching of external resources when parsing WSDL or XSD documents. However, in versions 4.0.0 through 4.3.2, this setting is defined but not enforced, allowing an attacker to potentially fetch malicious content from attacker-controlled URLs. Evidence is limited to public CVE and NVD information.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-58501 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-58501
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-58501 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-58501
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/mvantellingen/python-zeep/commit/83eb07bc6c84d841329d4f88856fecdba86f753e
[email protected] - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/mvantellingen/python-zeep/releases/tag/4.3.3
[email protected] - Release Notes
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/mvantellingen/python-zeep/security/advisories/GHSA-4cc2-g9w2-fhf6
[email protected] - Mitigation, Patch, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.