ELA-1836-1 lxml security update

multiple vulnerabilities

2026-09-30
Packagelxml
Version3.7.1-1+deb9u6 (stretch), 4.3.2-1+deb10u5 (buster), 4.6.3+dfsg-0.1+deb11u2 (bullseye)
Related CVEs CVE-2022-2309 CVE-2026-28348 CVE-2026-28350 CVE-2026-41066 CVE-2026-49825


Multiple vulnerabilities were discovered in lxml, a set pythonic binding for the libxml2 and libxslt libraries, which may lead to information disclosure, privilege escalation or denial of service.

CVE-2026-28348

The CSS @import filter is prone to bypass via unicode escapes, which may lead to information disclosure or privilege escalation.

CVE-2026-28350

The default Cleaner configuration is prone to <base> tag injection, thereby allowing an attacker to hijack relative links on the page.

CVE-2026-41066

Qiu Sihao discovered that the default configuration of iterparse() and ETCompatXMLParser() allows XML External Entity attacks to local files, which may lead to information disclosure.

CVE-2026-49825

Guillem Lefait discovered that the Cleaner module fails to strip javascript: URLs from namespaced URL attributes (xlink:href), which may lead to information disclosure or privilege escalation.

CVE-2022-2309

NULL Pointer Dereference in function _appendStartNsEvents() which may lead to denial of service.



For Debian 10 buster, these problems have been fixed in version 4.3.2-1+deb10u5.

For Debian 11 bullseye, these problems have been fixed in version 4.6.3+dfsg-0.1+deb11u2.

For Debian 9 stretch, these problems have been fixed in version 3.7.1-1+deb9u6.

We recommend that you upgrade your lxml packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.