python-lxml-4.2.3-5.el8_10
エラータID: AXSA:2026-1874:02
Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.
Security Fix(es):
* lxml: lxml-html-clean: lxml: URL bypass vulnerability in Cleaner via missing xlink:href (CVE-2026-49825)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-49825
lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.
Update packages.
lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.
N/A
SRPMS
- python-lxml-4.2.3-5.el8_10.src.rpm
MD5: 3787bb03024e615c104637876d9f5dc2
SHA-256: 034ee3f8b32b33ce3d0fa1baa24dc50a4ec317a401f76ddf700b394d3fb92691
Size: 4.28 MB
Asianux Server 8 for x86_64
- python3-lxml-4.2.3-5.el8_10.x86_64.rpm
MD5: fe806ef48a539444c4eb3e39465f9ef8
SHA-256: 02359f5011951f9bac5c22a687227b6d380d9e9278453273ae1a81061d8a643a
Size: 1.50 MB