Skip to content

Support lxml v6.1.0 #415

Description

@quentin-alc

LXML released the version 6.1.0 to fix a vulnerability GHSA-vfmq-68hx-4jfw

Running xmlsec 1.3.17 with lxml version 6.1.0 raise an InternalError:
xmlsec.InternalError: (-1, 'lxml & xmlsec libxml2 library version mismatch')

Activity

  1. mxamin commented on Apr 22, 2026

    @mxamin
    Collaborator

    @quentin-alc xmlsec 1.3.17 should be compatible with lxml 6.1.0. The error you see indicates that installed xmlsec and lxml use a different version of libxml2. I'm trying to remove this limitation, but it's not that easy to handle :)
    If you use the pre-build wheels, you won't see such issue, it only happens when you build the library locally using the local libxml2 which probably doesn't match the version that lxml is build with.

    If you give me the following information, I can investigate and help you with a solution:

    • Python version?
    • OS?
    • The command you use to install lxml and xmlsec?

    If you need more information, you can look into #356

  2. quentin-alc commented on Apr 22, 2026

    @quentin-alc
    Author

    Thank you for the quick response

    The python version is 3.12

    For the OS we use Ubuntu 20.04.06 LTS, here are all the informations:

    $ cat /etc/os-release
    NAME="Ubuntu"
    VERSION="20.04.6 LTS (Focal Fossa)"
    ID=ubuntu
    ID_LIKE=debian
    PRETTY_NAME="Ubuntu 20.04.6 LTS"
    VERSION_ID="20.04"
    HOME_URL="https://www.ubuntu.com/"
    SUPPORT_URL="https://help.ubuntu.com/"
    BUG_REPORT_URL="https://bugs.launchpad.net/ubuntu/"
    PRIVACY_POLICY_URL="https://www.ubuntu.com/legal/terms-and-policies/privacy-policy"
    VERSION_CODENAME=focal
    UBUNTU_CODENAME=focal
    

    We use uv to manage our dependencies. We have a uv.lock file that is generated and then on the server uv sync --frozen to sync the libraries.

    I will try to setup a small project that I can share with you that replicate the issue.

  3. mxamin commented on Apr 22, 2026

    @mxamin
    Collaborator

    That would be great if you can give me a sample to replicate the issue.
    Based on your setup, you can easily use the pre-build wheels, and it should work right out of the box.
    I recommend uninstalling both libs, clearing the cache and reinstall both lxml and xmlsec:

    uv pip uninstall lxml xmlsec
    uv cache clean
    uv pip install lxml==6.1.0 xmlsec==1.3.17
    
  4. quentin-alc commented on Apr 22, 2026

    @quentin-alc
    Author

    I created a small app to try to demonstrate it and it works on the same server, with same python version and dependencies manager.
    It still doesn't work on my main project but since I can get it working on another example, the issue is probably on my side. I'll try to clean the caches and see how it goes.

    Thanks for the support and sorry for the issue

  5. mxamin commented on Apr 22, 2026

    @mxamin
    Collaborator

    No problem :)

  6. quentin-alc commented on Apr 22, 2026

    @quentin-alc
    Author

    For future reference, if anyone encounters the same issue: I managed to isolate the cause to a conflict between uWSGI and the xmlsec/lxml libraries.

    The code runs perfectly when executed directly via the Python interpreter, but fails under uWSGI with the following error:

    File ".../.venv/lib/python3.12/site-packages/onelogin/saml2/utils.py", line 23, in <module>
        import xmlsec
    xmlsec.InternalError: (-1, 'lxml & xmlsec libxml2 library version mismatch')
    unable to load app 0 (mountpoint='') (callable not found or import error)
    *** no app loaded. going in full dynamic mode ***
    *** uWSGI is running in multiple interpreter mode ***
    

    From what I understand, uWSGI loads the system's shared libxml2 library. When the Python application later tries to load lxml or xmlsec a version mismatch occurs because the libxml2 lib on the system might be different than the one in the wheels, leading to the InternalError

  7. wrvdklooster commented on May 3, 2026

    @wrvdklooster

    @quentin-alc Maybe you already fixed this but just as a FYI on how we fixed it. This is from our Dockerfile. We do not use any xml configs in our set-up so removed the library in uwsgi.

    # Build uwsgi without xml support so we prevent issues between lxml and xmlsec libxml2 version.
    # Otherwise xmlsec uses the dynamically loaded libxml2 version from uwsgi.
    RUN uv pip uninstall uwsgi && UWSGI_PROFILE_OVERRIDE="xml=false" uv pip install uwsgi --no-binary :all: --no-cache
    
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions