<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:05:52 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:66203 — Important: python3.12-lxml security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:66203</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: python3.12-lxml&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* lxml: lxml-html-clean: lxml: URL bypass vulnerability in Cleaner via missing xlink:href (CVE-2026-49825)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: python3.12-lxml&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* lxml: lxml-html-clean: lxml: URL bypass vulnerability in Cleaner via missing xlink:href (CVE-2026-49825)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:66203</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-49825</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-49825</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: py3-lxml, Alpaquita:25: py3-lxml, Alpaquita:stream: py3-lxml&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: py3-lxml, Alpaquita:25: py3-lxml, Alpaquita:stream: py3-lxml&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-49825</guid>
    </item>
    <item>
      <title>BREW-gptline-CVE-2026-49825 — `lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes</title>
      <link>https://cve.radiocsirt.org/vuln/brew-gptline-cve-2026-49825</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: gptline&lt;/p&gt;
&lt;p&gt;# `lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes (`xlink:href`)&lt;/p&gt;
&lt;p&gt;**Reporter:** Guillem Lefait &amp;lt;guillem@datamq.com&amp;gt; · **Date:** 2026-05-10
**Affected:** `lxml` ≤ 6.1.0 and `lxml_html_clean` ≤ 0.4.4 (latest stable)
**Confirmed against:** lxml 6.1.0 + lxml_html_clean 0.4.4 on Python 3.13.5, 3.14.4, and 3.15.0a8 (libxml2 2.14.6 / 2.9.14 — bug is in pure-Python sanitizer logic, independent of the libxml2 backend)
**Root-cause class:** same as CVE-2021-28957 (`formaction` missing from `link_attrs`)&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`Cleaner` filters URL schemes (`javascript:`, `vbscript:`, …) by walking links via `rewrite_links()`, which delegates to `iterlinks()`, which only yields attributes named in `lxml.html.defs.link_attrs`. That allow-list contains no prefixed names (`xlink:href`) and no `srcset`. As a result, when `Cleaner` is configured with `safe_attrs_only=False` — a documented option for callers that want lenient attribute handling but still expect URL-scheme scrubbing — `&amp;lt;a xlink:href=&amp;#34;javascript:…&amp;#34;&amp;gt;` survives sanitization untouched, and any browser that follows the SVG-anchor specification will execute the JavaScript when the rendered link is clicked.&lt;/p&gt;
&lt;p&gt;**CWE:** CWE-79 (XSS), with CWE-184 (Incomplete List of Disallowed Inputs) as the underlying defect class.&lt;/p&gt;
&lt;p&gt;## Affected components&lt;/p&gt;
&lt;p&gt;| Package            | Versions tested        | File / line                      |
|--------------------|------------------------|----------------------------------|…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: gptline&lt;/p&gt;
&lt;p&gt;# `lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes (`xlink:href`)&lt;/p&gt;
&lt;p&gt;**Reporter:** Guillem Lefait &amp;lt;guillem@datamq.com&amp;gt; · **Date:** 2026-05-10
**Affected:** `lxml` ≤ 6.1.0 and `lxml_html_clean` ≤ 0.4.4 (latest stable)
**Confirmed against:** lxml 6.1.0 + lxml_html_clean 0.4.4 on Python 3.13.5, 3.14.4, and 3.15.0a8 (libxml2 2.14.6 / 2.9.14 — bug is in pure-Python sanitizer logic, independent of the libxml2 backend)
**Root-cause class:** same as CVE-2021-28957 (`formaction` missing from `link_attrs`)&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`Cleaner` filters URL schemes (`javascript:`, `vbscript:`, …) by walking links via `rewrite_links()`, which delegates to `iterlinks()`, which only yields attributes named in `lxml.html.defs.link_attrs`. That allow-list contains no prefixed names (`xlink:href`) and no `srcset`. As a result, when `Cleaner` is configured with `safe_attrs_only=False` — a documented option for callers that want lenient attribute handling but still expect URL-scheme scrubbing — `&amp;lt;a xlink:href=&amp;#34;javascript:…&amp;#34;&amp;gt;` survives sanitization untouched, and any browser that follows the SVG-anchor specification will execute the JavaScript when the rendered link is clicked.&lt;/p&gt;
&lt;p&gt;**CWE:** CWE-79 (XSS), with CWE-184 (Incomplete List of Disallowed Inputs) as the underlying defect class.&lt;/p&gt;
&lt;p&gt;## Affected components&lt;/p&gt;
&lt;p&gt;| Package            | Versions tested        | File / line                      |
|--------------------|------------------------|----------------------------------|…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-gptline-cve-2026-49825</guid>
    </item>
    <item>
      <title>EUVD-2026-357417</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-357417</link>
      <description>EUVD-2026-357417</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-357417</guid>
    </item>
    <item>
      <title>fkie_cve-2026-49825</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-49825</link>
      <description>&lt;p&gt;lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-49825</guid>
    </item>
    <item>
      <title>GHSA-4jhm-jv67-739f — `lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4jhm-jv67-739f</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: lxml_html_clean&lt;/p&gt;
&lt;p&gt;# `lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes (`xlink:href`)&lt;/p&gt;
&lt;p&gt;**Reporter:** Guillem Lefait &amp;lt;guillem@datamq.com&amp;gt; · **Date:** 2026-05-10
**Affected:** `lxml` ≤ 6.1.0 and `lxml_html_clean` ≤ 0.4.4 (latest stable)
**Confirmed against:** lxml 6.1.0 + lxml_html_clean 0.4.4 on Python 3.13.5, 3.14.4, and 3.15.0a8 (libxml2 2.14.6 / 2.9.14 — bug is in pure-Python sanitizer logic, independent of the libxml2 backend)
**Root-cause class:** same as CVE-2021-28957 (`formaction` missing from `link_attrs`)&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`Cleaner` filters URL schemes (`javascript:`, `vbscript:`, …) by walking links via `rewrite_links()`, which delegates to `iterlinks()`, which only yields attributes named in `lxml.html.defs.link_attrs`. That allow-list contains no prefixed names (`xlink:href`) and no `srcset`. As a result, when `Cleaner` is configured with `safe_attrs_only=False` — a documented option for callers that want lenient attribute handling but still expect URL-scheme scrubbing — `&amp;lt;a xlink:href=&amp;#34;javascript:…&amp;#34;&amp;gt;` survives sanitization untouched, and any browser that follows the SVG-anchor specification will execute the JavaScript when the rendered link is clicked.&lt;/p&gt;
&lt;p&gt;**CWE:** CWE-79 (XSS), with CWE-184 (Incomplete List of Disallowed Inputs) as the underlying defect class.&lt;/p&gt;
&lt;p&gt;## Affected components&lt;/p&gt;
&lt;p&gt;| Package            | Versions tested        | File / line                      |
|--------------------|------------------------|----------------------------------|…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: lxml_html_clean&lt;/p&gt;
&lt;p&gt;# `lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes (`xlink:href`)&lt;/p&gt;
&lt;p&gt;**Reporter:** Guillem Lefait &amp;lt;guillem@datamq.com&amp;gt; · **Date:** 2026-05-10
**Affected:** `lxml` ≤ 6.1.0 and `lxml_html_clean` ≤ 0.4.4 (latest stable)
**Confirmed against:** lxml 6.1.0 + lxml_html_clean 0.4.4 on Python 3.13.5, 3.14.4, and 3.15.0a8 (libxml2 2.14.6 / 2.9.14 — bug is in pure-Python sanitizer logic, independent of the libxml2 backend)
**Root-cause class:** same as CVE-2021-28957 (`formaction` missing from `link_attrs`)&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`Cleaner` filters URL schemes (`javascript:`, `vbscript:`, …) by walking links via `rewrite_links()`, which delegates to `iterlinks()`, which only yields attributes named in `lxml.html.defs.link_attrs`. That allow-list contains no prefixed names (`xlink:href`) and no `srcset`. As a result, when `Cleaner` is configured with `safe_attrs_only=False` — a documented option for callers that want lenient attribute handling but still expect URL-scheme scrubbing — `&amp;lt;a xlink:href=&amp;#34;javascript:…&amp;#34;&amp;gt;` survives sanitization untouched, and any browser that follows the SVG-anchor specification will execute the JavaScript when the rendered link is clicked.&lt;/p&gt;
&lt;p&gt;**CWE:** CWE-79 (XSS), with CWE-184 (Incomplete List of Disallowed Inputs) as the underlying defect class.&lt;/p&gt;
&lt;p&gt;## Affected components&lt;/p&gt;
&lt;p&gt;| Package            | Versions tested        | File / line                      |
|--------------------|------------------------|----------------------------------|…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4jhm-jv67-739f</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-49825 — lxml: javascript: URL bypass in Cleaner via xlink:href</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-49825</link>
      <description>msrc_CVE-2026-49825</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-49825</guid>
    </item>
    <item>
      <title>OESA-2026-3217 — python-lxml security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3217</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: python-lxml, openEuler:24.03-LTS-SP3: python-lxml, openEuler:24.03-LTS-SP4: python-lxml, openEuler:20.03-LTS-SP4: python-lxml, openEuler:22.03-LTS-SP4: python-lxml&lt;/p&gt;
&lt;p&gt;\&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;lxml_html_clean.Cleaner does not strip javascript: URLs from namespaced URL attributes (xlink:href). The vulnerability exists because Cleaner filters URL schemes by walking links via rewrite_links(), which delegates to iterlinks(), which only yields attributes named in lxml.html.defs.link_attrs. That allow-list contains no prefixed names such as xlink:href. As a result, when Cleaner is configured with safe_attrs_only=False, an xlink:href attribute carrying a javascript: URL survives sanitization untouched, and any browser that follows the SVG or MathML anchor specification will execute the JavaScript when the rendered link is clicked, leading to Cross-Site Scripting (XSS) attacks.(CVE-2026-49825)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: python-lxml, openEuler:24.03-LTS-SP3: python-lxml, openEuler:24.03-LTS-SP4: python-lxml, openEuler:20.03-LTS-SP4: python-lxml, openEuler:22.03-LTS-SP4: python-lxml&lt;/p&gt;
&lt;p&gt;\&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;lxml_html_clean.Cleaner does not strip javascript: URLs from namespaced URL attributes (xlink:href). The vulnerability exists because Cleaner filters URL schemes by walking links via rewrite_links(), which delegates to iterlinks(), which only yields attributes named in lxml.html.defs.link_attrs. That allow-list contains no prefixed names such as xlink:href. As a result, when Cleaner is configured with safe_attrs_only=False, an xlink:href attribute carrying a javascript: URL survives sanitization untouched, and any browser that follows the SVG or MathML anchor specification will execute the JavaScript when the rendered link is clicked, leading to Cross-Site Scripting (XSS) attacks.(CVE-2026-49825)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3217</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11147-1 — python-lxml-doc-6.1.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11147-1</link>
      <description>&lt;p&gt;python-lxml-doc-6.1.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python-lxml-doc-6.1.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11147-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-2614 — `lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2614</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: lxml-html-clean&lt;/p&gt;
&lt;p&gt;# `lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes (`xlink:href`)&lt;/p&gt;
&lt;p&gt;**Reporter:** Guillem Lefait &amp;lt;guillem@datamq.com&amp;gt; · **Date:** 2026-05-10
**Affected:** `lxml` ≤ 6.1.0 and `lxml_html_clean` ≤ 0.4.4 (latest stable)
**Confirmed against:** lxml 6.1.0 + lxml_html_clean 0.4.4 on Python 3.13.5, 3.14.4, and 3.15.0a8 (libxml2 2.14.6 / 2.9.14 — bug is in pure-Python sanitizer logic, independent of the libxml2 backend)
**Root-cause class:** same as CVE-2021-28957 (`formaction` missing from `link_attrs`)&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`Cleaner` filters URL schemes (`javascript:`, `vbscript:`, …) by walking links via `rewrite_links()`, which delegates to `iterlinks()`, which only yields attributes named in `lxml.html.defs.link_attrs`. That allow-list contains no prefixed names (`xlink:href`) and no `srcset`. As a result, when `Cleaner` is configured with `safe_attrs_only=False` — a documented option for callers that want lenient attribute handling but still expect URL-scheme scrubbing — `&amp;lt;a xlink:href=&amp;#34;javascript:…&amp;#34;&amp;gt;` survives sanitization untouched, and any browser that follows the SVG-anchor specification will execute the JavaScript when the rendered link is clicked.&lt;/p&gt;
&lt;p&gt;**CWE:** CWE-79 (XSS), with CWE-184 (Incomplete List of Disallowed Inputs) as the underlying defect class.&lt;/p&gt;
&lt;p&gt;## Affected components&lt;/p&gt;
&lt;p&gt;| Package            | Versions tested        | File / line                      |
|--------------------|------------------------|----------------------------------|…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: lxml-html-clean&lt;/p&gt;
&lt;p&gt;# `lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes (`xlink:href`)&lt;/p&gt;
&lt;p&gt;**Reporter:** Guillem Lefait &amp;lt;guillem@datamq.com&amp;gt; · **Date:** 2026-05-10
**Affected:** `lxml` ≤ 6.1.0 and `lxml_html_clean` ≤ 0.4.4 (latest stable)
**Confirmed against:** lxml 6.1.0 + lxml_html_clean 0.4.4 on Python 3.13.5, 3.14.4, and 3.15.0a8 (libxml2 2.14.6 / 2.9.14 — bug is in pure-Python sanitizer logic, independent of the libxml2 backend)
**Root-cause class:** same as CVE-2021-28957 (`formaction` missing from `link_attrs`)&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`Cleaner` filters URL schemes (`javascript:`, `vbscript:`, …) by walking links via `rewrite_links()`, which delegates to `iterlinks()`, which only yields attributes named in `lxml.html.defs.link_attrs`. That allow-list contains no prefixed names (`xlink:href`) and no `srcset`. As a result, when `Cleaner` is configured with `safe_attrs_only=False` — a documented option for callers that want lenient attribute handling but still expect URL-scheme scrubbing — `&amp;lt;a xlink:href=&amp;#34;javascript:…&amp;#34;&amp;gt;` survives sanitization untouched, and any browser that follows the SVG-anchor specification will execute the JavaScript when the rendered link is clicked.&lt;/p&gt;
&lt;p&gt;**CWE:** CWE-79 (XSS), with CWE-184 (Incomplete List of Disallowed Inputs) as the underlying defect class.&lt;/p&gt;
&lt;p&gt;## Affected components&lt;/p&gt;
&lt;p&gt;| Package            | Versions tested        | File / line                      |
|--------------------|------------------------|----------------------------------|…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2614</guid>
    </item>
    <item>
      <title>RHSA-2026:67279 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.7 Container Release Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:67279</link>
      <description>&lt;p&gt;ansible-automation-platform: privilege escalation via excessive group writable /etc/passwd permissions Automation-Controller: automation-controller: Kubernetes service account token exfiltration via HashiCorp Vault credential SSRF brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function django: Django: Remote code execution via GeoDjango spatial lookups GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks GitPython: GitPython: Arbitrary code execution via improper validation of clone options mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration lxml: lxml-html-clean: lxml: URL bypass vulnerability in Cleaner via missing xlink:href sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing protobufjs: protobufjs: Denial of Service via crafted .proto schema sqlparse: sqlparse: Denial of Service via inefficient SQL parsing gitpython: GitPython: Environment variable exfiltration via attacker-controlled clone URL gitpython: GitPython: Arbitrary code execution via command injection due to unguarded Git options gitpython: GitPython: Command Injection via Git option prefix abbreviation brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation postcss: PostCSS: Information disclosure via crafted sourceMappingURL aiohttp: AIOHTTP:…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ansible-automation-platform: privilege escalation via excessive group writable /etc/passwd permissions Automation-Controller: automation-controller: Kubernetes service account token exfiltration via HashiCorp Vault credential SSRF brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function django: Django: Remote code execution via GeoDjango spatial lookups GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks GitPython: GitPython: Arbitrary code execution via improper validation of clone options mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration lxml: lxml-html-clean: lxml: URL bypass vulnerability in Cleaner via missing xlink:href sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing protobufjs: protobufjs: Denial of Service via crafted .proto schema sqlparse: sqlparse: Denial of Service via inefficient SQL parsing gitpython: GitPython: Environment variable exfiltration via attacker-controlled clone URL gitpython: GitPython: Arbitrary code execution via command injection due to unguarded Git options gitpython: GitPython: Command Injection via Git option prefix abbreviation brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation postcss: PostCSS: Information disclosure via crafted sourceMappingURL aiohttp: AIOHTTP:…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:67279</guid>
    </item>
    <item>
      <title>RLSA-2026:66203 — Important: python3.12-lxml security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:66203</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: python3.12-lxml&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* lxml: lxml-html-clean: lxml: URL bypass vulnerability in Cleaner via missing xlink:href (CVE-2026-49825)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: python3.12-lxml&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* lxml: lxml-html-clean: lxml: URL bypass vulnerability in Cleaner via missing xlink:href (CVE-2026-49825)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:66203</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-49825</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-49825</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: lxml, Ubuntu:Pro:16.04:LTS: lxml, Ubuntu:18.04:LTS: lxml, Ubuntu:20.04:LTS: lxml, Ubuntu:22.04:LTS: lxml, Ubuntu:24.04:LTS: lxml, Ubuntu:26.04:LTS: lxml&lt;/p&gt;
&lt;p&gt;lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: lxml, Ubuntu:Pro:16.04:LTS: lxml, Ubuntu:18.04:LTS: lxml, Ubuntu:20.04:LTS: lxml, Ubuntu:22.04:LTS: lxml, Ubuntu:24.04:LTS: lxml, Ubuntu:26.04:LTS: lxml&lt;/p&gt;
&lt;p&gt;lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-49825</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3292 — Red Hat Enterprise Linux (lxml): Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3292</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3292</guid>
    </item>
  </channel>
</rss>
