<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T13:06:32.674440+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:66203</id>
    <title>ALSA-2026:66203 — Important: python3.12-lxml security update</title>
    <updated>2026-10-02T13:06:32.756300+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: python3.12-lxml</p>
<p>Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.</p>
<p>Security Fix(es):</p>
<p>* lxml: lxml-html-clean: lxml: URL bypass vulnerability in Cleaner via missing xlink:href (CVE-2026-49825)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:66203"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-49825</id>
    <title>BELL-CVE-2026-49825</title>
    <updated>2026-10-02T13:06:32.756388+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: py3-lxml, Alpaquita:25: py3-lxml, Alpaquita:stream: py3-lxml</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-49825"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-gptline-cve-2026-49825</id>
    <title>BREW-gptline-CVE-2026-49825 — `lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes</title>
    <updated>2026-10-02T13:06:32.756415+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: gptline</p>
<p># `lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes (`xlink:href`)</p>
<p>**Reporter:** Guillem Lefait &lt;guillem@datamq.com&gt; · **Date:** 2026-05-10
**Affected:** `lxml` ≤ 6.1.0 and `lxml_html_clean` ≤ 0.4.4 (latest stable)
**Confirmed against:** lxml 6.1.0 + lxml_html_clean 0.4.4 on Python 3.13.5, 3.14.4, and 3.15.0a8 (libxml2 2.14.6 / 2.9.14 — bug is in pure-Python sanitizer logic, independent of the libxml2 backend)
**Root-cause class:** same as CVE-2021-28957 (`formaction` missing from `link_attrs`)</p>
<p>## Summary</p>
<p>`Cleaner` filters URL schemes (`javascript:`, `vbscript:`, …) by walking links via `rewrite_links()`, which delegates to `iterlinks()`, which only yields attributes named in `lxml.html.defs.link_attrs`. That allow-list contains no prefixed names (`xlink:href`) and no `srcset`. As a result, when `Cleaner` is configured with `safe_attrs_only=False` — a documented option for callers that want lenient attribute handling but still expect URL-scheme scrubbing — `&lt;a xlink:href="javascript:…"&gt;` survives sanitization untouched, and any browser that follows the SVG-anchor specification will execute the JavaScript when the rendered link is clicked.</p>
<p>**CWE:** CWE-79 (XSS), with CWE-184 (Incomplete List of Disallowed Inputs) as the underlying defect class.</p>
<p>## Affected components</p>
<p>| Package            | Versions tested        | File / line                      |
|--------------------|------------------------|----------------------------------|…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-gptline-cve-2026-49825"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-357417</id>
    <title>EUVD-2026-357417</title>
    <updated>2026-10-02T13:06:32.756491+00:00</updated>
    <content>EUVD-2026-357417</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-357417"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-49825</id>
    <title>fkie_cve-2026-49825</title>
    <updated>2026-10-02T13:06:32.756505+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-49825"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4jhm-jv67-739f</id>
    <title>GHSA-4jhm-jv67-739f — `lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes</title>
    <updated>2026-10-02T13:06:32.756528+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: lxml_html_clean</p>
<p># `lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes (`xlink:href`)</p>
<p>**Reporter:** Guillem Lefait &lt;guillem@datamq.com&gt; · **Date:** 2026-05-10
**Affected:** `lxml` ≤ 6.1.0 and `lxml_html_clean` ≤ 0.4.4 (latest stable)
**Confirmed against:** lxml 6.1.0 + lxml_html_clean 0.4.4 on Python 3.13.5, 3.14.4, and 3.15.0a8 (libxml2 2.14.6 / 2.9.14 — bug is in pure-Python sanitizer logic, independent of the libxml2 backend)
**Root-cause class:** same as CVE-2021-28957 (`formaction` missing from `link_attrs`)</p>
<p>## Summary</p>
<p>`Cleaner` filters URL schemes (`javascript:`, `vbscript:`, …) by walking links via `rewrite_links()`, which delegates to `iterlinks()`, which only yields attributes named in `lxml.html.defs.link_attrs`. That allow-list contains no prefixed names (`xlink:href`) and no `srcset`. As a result, when `Cleaner` is configured with `safe_attrs_only=False` — a documented option for callers that want lenient attribute handling but still expect URL-scheme scrubbing — `&lt;a xlink:href="javascript:…"&gt;` survives sanitization untouched, and any browser that follows the SVG-anchor specification will execute the JavaScript when the rendered link is clicked.</p>
<p>**CWE:** CWE-79 (XSS), with CWE-184 (Incomplete List of Disallowed Inputs) as the underlying defect class.</p>
<p>## Affected components</p>
<p>| Package            | Versions tested        | File / line                      |
|--------------------|------------------------|----------------------------------|…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4jhm-jv67-739f"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-49825</id>
    <title>msrc_CVE-2026-49825 — lxml: javascript: URL bypass in Cleaner via xlink:href</title>
    <updated>2026-10-02T13:06:32.756648+00:00</updated>
    <content>msrc_CVE-2026-49825</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-49825"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3217</id>
    <title>OESA-2026-3217 — python-lxml security update</title>
    <updated>2026-10-02T13:06:32.756668+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: python-lxml, openEuler:24.03-LTS-SP3: python-lxml, openEuler:24.03-LTS-SP4: python-lxml, openEuler:20.03-LTS-SP4: python-lxml, openEuler:22.03-LTS-SP4: python-lxml</p>
<p>\

Security Fix(es):</p>
<p>lxml_html_clean.Cleaner does not strip javascript: URLs from namespaced URL attributes (xlink:href). The vulnerability exists because Cleaner filters URL schemes by walking links via rewrite_links(), which delegates to iterlinks(), which only yields attributes named in lxml.html.defs.link_attrs. That allow-list contains no prefixed names such as xlink:href. As a result, when Cleaner is configured with safe_attrs_only=False, an xlink:href attribute carrying a javascript: URL survives sanitization untouched, and any browser that follows the SVG or MathML anchor specification will execute the JavaScript when the rendered link is clicked, leading to Cross-Site Scripting (XSS) attacks.(CVE-2026-49825)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3217"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11147-1</id>
    <title>openSUSE-SU-2026:11147-1 — python-lxml-doc-6.1.1-1.1 on GA media</title>
    <updated>2026-10-02T13:06:32.756700+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python-lxml-doc-6.1.1-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11147-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2614</id>
    <title>PYSEC-2026-2614 — `lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes</title>
    <updated>2026-10-02T13:06:32.756719+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: lxml-html-clean</p>
<p># `lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes (`xlink:href`)</p>
<p>**Reporter:** Guillem Lefait &lt;guillem@datamq.com&gt; · **Date:** 2026-05-10
**Affected:** `lxml` ≤ 6.1.0 and `lxml_html_clean` ≤ 0.4.4 (latest stable)
**Confirmed against:** lxml 6.1.0 + lxml_html_clean 0.4.4 on Python 3.13.5, 3.14.4, and 3.15.0a8 (libxml2 2.14.6 / 2.9.14 — bug is in pure-Python sanitizer logic, independent of the libxml2 backend)
**Root-cause class:** same as CVE-2021-28957 (`formaction` missing from `link_attrs`)</p>
<p>## Summary</p>
<p>`Cleaner` filters URL schemes (`javascript:`, `vbscript:`, …) by walking links via `rewrite_links()`, which delegates to `iterlinks()`, which only yields attributes named in `lxml.html.defs.link_attrs`. That allow-list contains no prefixed names (`xlink:href`) and no `srcset`. As a result, when `Cleaner` is configured with `safe_attrs_only=False` — a documented option for callers that want lenient attribute handling but still expect URL-scheme scrubbing — `&lt;a xlink:href="javascript:…"&gt;` survives sanitization untouched, and any browser that follows the SVG-anchor specification will execute the JavaScript when the rendered link is clicked.</p>
<p>**CWE:** CWE-79 (XSS), with CWE-184 (Incomplete List of Disallowed Inputs) as the underlying defect class.</p>
<p>## Affected components</p>
<p>| Package            | Versions tested        | File / line                      |
|--------------------|------------------------|----------------------------------|…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2614"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:67279</id>
    <title>RHSA-2026:67279 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.7 Container Release Update</title>
    <updated>2026-10-02T13:06:32.756790+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ansible-automation-platform: privilege escalation via excessive group writable /etc/passwd permissions Automation-Controller: automation-controller: Kubernetes service account token exfiltration via HashiCorp Vault credential SSRF brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function django: Django: Remote code execution via GeoDjango spatial lookups GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks GitPython: GitPython: Arbitrary code execution via improper validation of clone options mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration lxml: lxml-html-clean: lxml: URL bypass vulnerability in Cleaner via missing xlink:href sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing protobufjs: protobufjs: Denial of Service via crafted .proto schema sqlparse: sqlparse: Denial of Service via inefficient SQL parsing gitpython: GitPython: Environment variable exfiltration via attacker-controlled clone URL gitpython: GitPython: Arbitrary code execution via command injection due to unguarded Git options gitpython: GitPython: Command Injection via Git option prefix abbreviation brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation postcss: PostCSS: Information disclosure via crafted sourceMappingURL aiohttp: AIOHTTP:…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:67279"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:66203</id>
    <title>RLSA-2026:66203 — Important: python3.12-lxml security update</title>
    <updated>2026-10-02T13:06:32.756859+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: python3.12-lxml</p>
<p>Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.</p>
<p>Security Fix(es):</p>
<p>* lxml: lxml-html-clean: lxml: URL bypass vulnerability in Cleaner via missing xlink:href (CVE-2026-49825)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:66203"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-49825</id>
    <title>UBUNTU-CVE-2026-49825</title>
    <updated>2026-10-02T13:06:32.756883+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: lxml, Ubuntu:Pro:16.04:LTS: lxml, Ubuntu:18.04:LTS: lxml, Ubuntu:20.04:LTS: lxml, Ubuntu:22.04:LTS: lxml, Ubuntu:24.04:LTS: lxml, Ubuntu:26.04:LTS: lxml</p>
<p>lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-49825"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3292</id>
    <title>WID-SEC-W-2026-3292 — Red Hat Enterprise Linux (lxml): Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
    <updated>2026-10-02T13:06:32.756911+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3292"/>
  </entry>
</feed>
