UbuntuUpdates.org

Package "python3-lxml"

Name: python3-lxml

Description:

pythonic binding for the libxml2 and libxslt libraries

Latest version: 5.2.1-1ubuntu0.2
Release: noble (24.04)
Level: updates
Repository: main
Head package: lxml
Homepage: http://lxml.de/

Links


Download "python3-lxml"


Other versions of "python3-lxml" in Noble

Repository Area Version
base main 5.2.1-1
security main 5.2.1-1ubuntu0.2
proposed main 5.2.1-1ubuntu0.1

Changelog

Version: 5.2.1-1ubuntu0.2 2026-10-08 07:07:20 UTC

lxml (5.2.1-1ubuntu0.2) noble-security; urgency=medium

  * SECURITY UPDATE: Cross-site scripting
    - debian/patches/CVE-2026-49825.patch: add 'xlink:href' to the
      known HTML link attributes in src/lxml/html/defs.py so that
      Cleaner/rewrite_links() sanitize javascript: URLs in embedded
      SVG/MathML content, and add a regression test to
      src/lxml/html/tests/test_rewritelinks.txt.
    - CVE-2026-49825
  * SECURITY UPDATE: XML external entity injection
    - debian/patches/CVE-2026-41066.patch: set
      resolve_entities='internal' as the default for iterparse() and
      ETCompatXMLParser() in src/lxml/iterparse.pxi and
      src/lxml/parser.pxi, and add a regression test to
      src/lxml/tests/test_etree.py.
    - CVE-2026-41066
  * debian/rules: export WITH_CYTHON=true so the build regenerates
    the C extension from the patched Cython sources instead of using
    the pre-generated C files shipped in the upstream tarball.

 -- Allen Huang Thu, 01 Oct 2026 14:25:52 +0100

CVE-2026-49825 lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing `
CVE-2026-41066 lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in the default configuration (w



About   -   Send Feedback to @ubuntu_updates