<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 08:10:15 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:1763 — Moderate: python39:3.9 and python39-devel:3.9 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:1763</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: python39, AlmaLinux:8: python39-Cython, AlmaLinux:8: python39-PyMySQL, AlmaLinux:8: python39-attrs, AlmaLinux:8: python39-cffi, AlmaLinux:8: python39-chardet, AlmaLinux:8: python39-cryptography, AlmaLinux:8: python39-debug, AlmaLinux:8: python39-devel, AlmaLinux:8: python39-idle and 39 more&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python-lxml: HTML Cleaner allows crafted and SVG embedded scripts to pass through (CVE-2021-43818)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: python39, AlmaLinux:8: python39-Cython, AlmaLinux:8: python39-PyMySQL, AlmaLinux:8: python39-attrs, AlmaLinux:8: python39-cffi, AlmaLinux:8: python39-chardet, AlmaLinux:8: python39-cryptography, AlmaLinux:8: python39-debug, AlmaLinux:8: python39-devel, AlmaLinux:8: python39-idle and 39 more&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python-lxml: HTML Cleaner allows crafted and SVG embedded scripts to pass through (CVE-2021-43818)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:1763</guid>
    </item>
    <item>
      <title>bdu:2022-00756</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-00756</link>
      <description>bdu:2022-00756</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-00756</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2021-43818 — CVE-2021-43818 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2021-43818</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2021-43818</guid>
    </item>
    <item>
      <title>BREW-ansible-CVE-2021-43818 — lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through</title>
      <link>https://cve.radiocsirt.org/vuln/brew-ansible-cve-2021-43818</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible&lt;/p&gt;
&lt;p&gt;### Impact
The HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs.&lt;/p&gt;
&lt;p&gt;Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5.&lt;/p&gt;
&lt;p&gt;### Patches
The issue has been resolved in lxml 4.6.5.&lt;/p&gt;
&lt;p&gt;### Workarounds
None.&lt;/p&gt;
&lt;p&gt;### References
The issues are tracked under the report IDs GHSL-2021-1037 and GHSL-2021-1038.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible&lt;/p&gt;
&lt;p&gt;### Impact
The HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs.&lt;/p&gt;
&lt;p&gt;Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5.&lt;/p&gt;
&lt;p&gt;### Patches
The issue has been resolved in lxml 4.6.5.&lt;/p&gt;
&lt;p&gt;### Workarounds
None.&lt;/p&gt;
&lt;p&gt;### References
The issues are tracked under the report IDs GHSL-2021-1037 and GHSL-2021-1038.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-ansible-cve-2021-43818</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0262 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0262</link>
      <description>certfr-2024-avi-0262</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0262</guid>
    </item>
    <item>
      <title>cnvd-2021-100235</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-100235</link>
      <description>cnvd-2021-100235</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-100235</guid>
    </item>
    <item>
      <title>EUVD-2026-263982</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-263982</link>
      <description>EUVD-2026-263982</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-263982</guid>
    </item>
    <item>
      <title>fkie_cve-2021-43818</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-43818</link>
      <description>&lt;p&gt;lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5 to receive a patch. There are no known workarounds available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5 to receive a patch. There are no known workarounds available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-43818</guid>
    </item>
    <item>
      <title>GHSA-55x5-fj6c-h6m8 — lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-55x5-fj6c-h6m8</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: lxml&lt;/p&gt;
&lt;p&gt;### Impact
The HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs.&lt;/p&gt;
&lt;p&gt;Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5.&lt;/p&gt;
&lt;p&gt;### Patches
The issue has been resolved in lxml 4.6.5.&lt;/p&gt;
&lt;p&gt;### Workarounds
None.&lt;/p&gt;
&lt;p&gt;### References
The issues are tracked under the report IDs GHSL-2021-1037 and GHSL-2021-1038.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: lxml&lt;/p&gt;
&lt;p&gt;### Impact
The HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs.&lt;/p&gt;
&lt;p&gt;Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5.&lt;/p&gt;
&lt;p&gt;### Patches
The issue has been resolved in lxml 4.6.5.&lt;/p&gt;
&lt;p&gt;### Workarounds
None.&lt;/p&gt;
&lt;p&gt;### References
The issues are tracked under the report IDs GHSL-2021-1037 and GHSL-2021-1038.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-55x5-fj6c-h6m8</guid>
    </item>
    <item>
      <title>gsd-2021-43818</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-43818</link>
      <description>gsd-2021-43818</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-43818</guid>
    </item>
    <item>
      <title>msrc_CVE-2021-43818 — HTML Cleaner allows crafted and SVG embedded scripts to pass through</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2021-43818</link>
      <description>msrc_CVE-2021-43818</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2021-43818</guid>
    </item>
    <item>
      <title>OESA-2022-1482 — python-lxml security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1482</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: python-lxml, openEuler:20.03-LTS-SP2: python-lxml, openEuler:20.03-LTS-SP3: python-lxml&lt;/p&gt;
&lt;p&gt;XML processing library combining libxml2/libxslt with the ElementTree API.&#13;
&#13;
Security Fix(es):&#13;
&#13;
lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5 to receive a patch. There are no known workarounds available.(CVE-2021-43818)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: python-lxml, openEuler:20.03-LTS-SP2: python-lxml, openEuler:20.03-LTS-SP3: python-lxml&lt;/p&gt;
&lt;p&gt;XML processing library combining libxml2/libxslt with the ElementTree API.&#13;
&#13;
Security Fix(es):&#13;
&#13;
lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5 to receive a patch. There are no known workarounds available.(CVE-2021-43818)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1482</guid>
    </item>
    <item>
      <title>openSUSE-SU-2022:0803-1 — Security update for python-lxml</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2022:0803-1</link>
      <description>&lt;p&gt;Security update for python-lxml&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-lxml&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2022:0803-1</guid>
    </item>
    <item>
      <title>PYSEC-2021-852</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2021-852</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: lxml&lt;/p&gt;
&lt;p&gt;lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5 to receive a patch. There are no known workarounds available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: lxml&lt;/p&gt;
&lt;p&gt;lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5 to receive a patch. There are no known workarounds available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2021-852</guid>
    </item>
    <item>
      <title>RHSA-2022:1664 — Red Hat Security Advisory: Red Hat Software Collections security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:1664</link>
      <description>&lt;p&gt;python-lxml: HTML Cleaner allows crafted and SVG embedded scripts to pass through&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python-lxml: HTML Cleaner allows crafted and SVG embedded scripts to pass through&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:1664</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:0803-1 — Security update for python-lxml</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:0803-1</link>
      <description>&lt;p&gt;Security update for python-lxml&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-lxml&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:0803-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-43818</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-43818</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: lxml, Ubuntu:Pro:16.04:LTS: lxml, Ubuntu:18.04:LTS: lxml, Ubuntu:20.04:LTS: lxml, Ubuntu:22.04:LTS: lxml&lt;/p&gt;
&lt;p&gt;lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5 to receive a patch. There are no known workarounds available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: lxml, Ubuntu:Pro:16.04:LTS: lxml, Ubuntu:18.04:LTS: lxml, Ubuntu:20.04:LTS: lxml, Ubuntu:22.04:LTS: lxml&lt;/p&gt;
&lt;p&gt;lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5 to receive a patch. There are no known workarounds available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-43818</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0302 — Xerox FreeFlow Print Server: Mehrere Schwachstellen ermöglichen Ausführen von beliebigem Programmcode mit Administrator…</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0302</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um beliebigen Programmcode auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen, Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um beliebigen Programmcode auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen, Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0302</guid>
    </item>
  </channel>
</rss>
