python-lxml-4.6.5-3.el9_8.1

エラータID: AXSA:2026-1823:01

Release date: 
Monday, September 14, 2026 - 20:15
Subject: 
python-lxml-4.6.5-3.el9_8.1
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.

Security Fix(es):

* lxml: lxml-html-clean: lxml: URL bypass vulnerability in Cleaner via missing xlink:href (CVE-2026-49825)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-49825
lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. python-lxml-4.6.5-3.el9_8.1.src.rpm
    MD5: 7ed13a9b91ce822fdbe21be4eddeb4a5
    SHA-256: ab957ac98abcb21d72bca8dbe969acd08c69f83c343fb631b146dc648fc33e08
    Size: 3.07 MB

Asianux Server 9 for x86_64
  1. python3-lxml-4.6.5-3.el9_8.1.x86_64.rpm
    MD5: cbe9074741b0e4d29765066fd16f0653
    SHA-256: 70991b3ddbdfa1575816af9ecaa40d7b31e44139649e808bc0d8defba07a7e9c
    Size: 1.22 MB