Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2242427
AlmaLinux
5975
Alpaquita
16176
Alpine
4655
Android
3708
Azure Linux
17971
BellSoft Hardened Containers
770
Bitnami
9501
Chainguard
1048512
CleanStart
5432
CRAN
14
crates.io
2768
Debian
68992
Echo
7853
GHC
3
GIT
109057
GitHub Actions
55
Go
9332
Hackage
33
Hex
365
Julia
1713
Linux
29975
Mageia
6237
Maven
7055
MinimOS
148636
npm
229266
NuGet
1869
opam
29
openEuler
8900
openSUSE
14647
OSS-Fuzz
4019
Packagist
7103
Pub
11
PyPI
25495
Red Hat
23535
Rocky Linux
4344
Root
19644
RubyGems
5369
SUSE
23455
SwiftURL
61
TuxCare
9974
Ubuntu
66090
VSCode
21
Wolfi
293807
ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-2614
PyPI/lxml-html-clean
`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes
13 Jul
Fix available
Severity - 8.2 (High)
GHSA-4jhm-jv67-739f
PyPI/lxml-html-clean
`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes
08 Jul
Fix available
Severity - 8.2 (High)
PYSEC-2026-87
PyPI/lxml
See record for full details
24 Apr
Fix available
Severity - 7.5 (High)
GHSA-vfmq-68hx-4jfw
PyPI/lxml
lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files
21 Apr
Fix available
Severity - 7.5 (High)
PYSEC-2026-2202
PyPI/lxml-html-clean
See record for full details
05 Mar
Fix available
Severity - 6.1 (Medium)
PYSEC-2026-2201
PyPI/lxml-html-clean
See record for full details
05 Mar
Fix available
Severity - 6.1 (Medium)
GHSA-xvp8-3mhv-424c
PyPI/lxml-html-clean
lxml-html-clean has <base> tag injection through default Cleaner configuration
02 Mar
Fix available
Severity - 6.1 (Medium)
GHSA-hw26-mmpg-fqfg
PyPI/lxml-html-clean
lxml-html-clean has CSS @import Filter Bypass via Unicode Escapes
02 Mar
Fix available
Severity - 6.1 (Medium)
PYSEC-2024-160
PyPI/lxml-html-clean
github.com/fedora-python/lxml_html_clean
See record for full details
19 Nov 2024
Fix available
Severity - 6.1 (Medium)
GHSA-5jfw-gq64-q45f
PyPI/lxml-html-clean
HTML Cleaner allows crafted scripts in special contexts like svg or math to pass through
19 Nov 2024
Fix available
Severity - 7.7 (High)
GHSA-wrxv-2j5q-m38w
PyPI/lxml
lxml NULL Pointer Dereference allows attackers to cause a denial of service
06 Jul 2022
Fix available
Severity - 6.9 (Medium)
PYSEC-2022-230
PyPI/lxml
github.com/lxml/lxml
See record for full details
05 Jul 2022
Fix available
GHSA-57qw-cc2g-pv5p
PyPI/lxml
lxml Cross-site Scripting Via Control Characters
14 May 2022
Fix available
Severity - 5.3 (Medium)
GHSA-xp26-p53h-6h2p
PyPI/lxml
Improper Neutralization of Input During Web Page Generation in LXML
13 May 2022
Fix available
Severity - 5.3 (Medium)
PYSEC-2021-852
PyPI/lxml
github.com/lxml/lxml
github.com/lxml/lxml#diff-59130575b4fb2932c957db2922977d7d89afb0b2085357db1a14615a2fcad776
See record for full details
13 Dec 2021
Fix available
GHSA-55x5-fj6c-h6m8
PyPI/lxml
lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through
13 Dec 2021
Fix available
Severity - 6.3 (Medium)
Load more...
PyPI - OSV