<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T19:13:38.515347+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:1763</id>
    <title>ALSA-2022:1763 — Moderate: python39:3.9 and python39-devel:3.9 security update</title>
    <updated>2026-10-03T19:13:39.536832+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: python39, AlmaLinux:8: python39-Cython, AlmaLinux:8: python39-PyMySQL, AlmaLinux:8: python39-attrs, AlmaLinux:8: python39-cffi, AlmaLinux:8: python39-chardet, AlmaLinux:8: python39-cryptography, AlmaLinux:8: python39-debug, AlmaLinux:8: python39-devel, AlmaLinux:8: python39-idle and 39 more</p>
<p>Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.</p>
<p>Security Fix(es):</p>
<p>* python-lxml: HTML Cleaner allows crafted and SVG embedded scripts to pass through (CVE-2021-43818)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:1763"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-00756</id>
    <title>bdu:2022-00756</title>
    <updated>2026-10-03T19:13:39.536971+00:00</updated>
    <content>bdu:2022-00756</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-00756"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2021-43818</id>
    <title>Withdrawn: BELL-CVE-2021-43818 — CVE-2021-43818 does not affect BellSoft software</title>
    <updated>2026-10-03T19:13:39.536990+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2021-43818"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-ansible-cve-2021-43818</id>
    <title>BREW-ansible-CVE-2021-43818 — lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through</title>
    <updated>2026-10-03T19:13:39.537006+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: ansible</p>
<p>### Impact
The HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs.</p>
<p>Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5.</p>
<p>### Patches
The issue has been resolved in lxml 4.6.5.</p>
<p>### Workarounds
None.</p>
<p>### References
The issues are tracked under the report IDs GHSL-2021-1037 and GHSL-2021-1038.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-ansible-cve-2021-43818"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0262</id>
    <title>certfr-2024-avi-0262 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
    <updated>2026-10-03T19:13:39.537033+00:00</updated>
    <content>certfr-2024-avi-0262</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0262"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-100235</id>
    <title>cnvd-2021-100235</title>
    <updated>2026-10-03T19:13:39.537050+00:00</updated>
    <content>cnvd-2021-100235</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-100235"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-263982</id>
    <title>EUVD-2026-263982</title>
    <updated>2026-10-03T19:13:39.537062+00:00</updated>
    <content>EUVD-2026-263982</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-263982"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-43818</id>
    <title>fkie_cve-2021-43818</title>
    <updated>2026-10-03T19:13:39.537072+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5 to receive a patch. There are no known workarounds available.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-43818"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-55x5-fj6c-h6m8</id>
    <title>GHSA-55x5-fj6c-h6m8 — lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through</title>
    <updated>2026-10-03T19:13:39.537094+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: lxml</p>
<p>### Impact
The HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs.</p>
<p>Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5.</p>
<p>### Patches
The issue has been resolved in lxml 4.6.5.</p>
<p>### Workarounds
None.</p>
<p>### References
The issues are tracked under the report IDs GHSL-2021-1037 and GHSL-2021-1038.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-55x5-fj6c-h6m8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-43818</id>
    <title>gsd-2021-43818</title>
    <updated>2026-10-03T19:13:39.537118+00:00</updated>
    <content>gsd-2021-43818</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-43818"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2021-43818</id>
    <title>msrc_CVE-2021-43818 — HTML Cleaner allows crafted and SVG embedded scripts to pass through</title>
    <updated>2026-10-03T19:13:39.537129+00:00</updated>
    <content>msrc_CVE-2021-43818</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2021-43818"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1482</id>
    <title>OESA-2022-1482 — python-lxml security update</title>
    <updated>2026-10-03T19:13:39.537145+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: python-lxml, openEuler:20.03-LTS-SP2: python-lxml, openEuler:20.03-LTS-SP3: python-lxml</p>
<p>XML processing library combining libxml2/libxslt with the ElementTree API.

Security Fix(es):

lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5 to receive a patch. There are no known workarounds available.(CVE-2021-43818)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1482"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2022:0803-1</id>
    <title>openSUSE-SU-2022:0803-1 — Security update for python-lxml</title>
    <updated>2026-10-03T19:13:39.537171+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-lxml</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2022:0803-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2021-852</id>
    <title>PYSEC-2021-852</title>
    <updated>2026-10-03T19:13:39.537189+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: lxml</p>
<p>lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5 to receive a patch. There are no known workarounds available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2021-852"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:1664</id>
    <title>RHSA-2022:1664 — Red Hat Security Advisory: Red Hat Software Collections security update</title>
    <updated>2026-10-03T19:13:39.537209+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python-lxml: HTML Cleaner allows crafted and SVG embedded scripts to pass through</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:1664"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:0803-1</id>
    <title>SUSE-SU-2022:0803-1 — Security update for python-lxml</title>
    <updated>2026-10-03T19:13:39.537225+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-lxml</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:0803-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-43818</id>
    <title>UBUNTU-CVE-2021-43818</title>
    <updated>2026-10-03T19:13:39.537242+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: lxml, Ubuntu:Pro:16.04:LTS: lxml, Ubuntu:18.04:LTS: lxml, Ubuntu:20.04:LTS: lxml, Ubuntu:22.04:LTS: lxml</p>
<p>lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5 to receive a patch. There are no known workarounds available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-43818"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0302</id>
    <title>WID-SEC-W-2022-0302 — Xerox FreeFlow Print Server: Mehrere Schwachstellen ermöglichen Ausführen von beliebigem Programmcode mit Administrator…</title>
    <updated>2026-10-03T19:13:39.537267+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um beliebigen Programmcode auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen, Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder Dateien zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0302"/>
  </entry>
</feed>
