python3.12-lxml-4.9.3-2.el9_8.1
エラータID: AXSA:2026-1813:01
Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.
Security Fix(es):
* lxml: lxml-html-clean: lxml: URL bypass vulnerability in Cleaner via missing xlink:href (CVE-2026-49825)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-49825
lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.
Update packages.
lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.
N/A
SRPMS
- python3.12-lxml-4.9.3-2.el9_8.1.src.rpm
MD5: 720095ada975f22b724056f63f44507d
SHA-256: 4fbe8db793a9fca746712bbe57045abe5e70ffbe9cf38c7823bb4c2ac583ffdd
Size: 3.51 MB
Asianux Server 9 for x86_64
- python3.12-lxml-4.9.3-2.el9_8.1.x86_64.rpm
MD5: 9d1e3df5ed6dfc5d1e0cd06121e644e1
SHA-256: b5512301215aaaddb15c4c4f92d0affe26802d517f58eb646634f09e456b4b3d
Size: 1.39 MB