| Package | lxml |
|---|---|
| Version | 3.7.1-1+deb9u6 (stretch), 4.3.2-1+deb10u5 (buster), 4.6.3+dfsg-0.1+deb11u2 (bullseye) |
| Related CVEs | CVE-2022-2309 CVE-2026-28348 CVE-2026-28350 CVE-2026-41066 CVE-2026-49825 |
Multiple vulnerabilities were discovered in lxml, a set pythonic binding for the libxml2 and libxslt libraries, which may lead to information disclosure, privilege escalation or denial of service.
- CVE-2026-28348
-
The CSS
@import filteris prone to bypass via unicode escapes, which may lead to information disclosure or privilege escalation. - CVE-2026-28350
-
The default
Cleanerconfiguration is prone to<base>tag injection, thereby allowing an attacker to hijack relative links on the page. - CVE-2026-41066
-
Qiu Sihao discovered that the default configuration of
iterparse()andETCompatXMLParser()allows XML External Entity attacks to local files, which may lead to information disclosure. - CVE-2026-49825
-
Guillem Lefait discovered that the Cleaner module fails to strip
javascript:URLs from namespaced URL attributes (xlink:href), which may lead to information disclosure or privilege escalation. - CVE-2022-2309
-
NULL Pointer Dereference in function
_appendStartNsEvents()which may lead to denial of service.
For Debian 10 buster, these problems have been fixed in version 4.3.2-1+deb10u5.
For Debian 11 bullseye, these problems have been fixed in version 4.6.3+dfsg-0.1+deb11u2.
For Debian 9 stretch, these problems have been fixed in version 3.7.1-1+deb9u6.
We recommend that you upgrade your lxml packages.
Further information about Extended LTS security advisories can be found in the dedicated section of our website.