Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2198389
AlmaLinux
5919
Alpaquita
15742
Alpine
4608
Android
3674
Azure Linux
17629
BellSoft Hardened Containers
745
Bitnami
9290
Chainguard
1023658
CleanStart
3591
CRAN
14
crates.io
2732
Debian
68356
Echo
6714
GHC
3
GIT
108035
GitHub Actions
55
Go
9203
Hackage
32
Hex
361
Julia
1713
Linux
29974
Mageia
6227
Maven
7040
MinimOS
144169
npm
228732
NuGet
1869
opam
29
openEuler
8800
openSUSE
14454
OSS-Fuzz
4013
Packagist
7095
Pub
11
PyPI
25158
Red Hat
23327
Rocky Linux
4292
Root
19534
RubyGems
5326
SUSE
23081
SwiftURL
60
TuxCare
9472
Ubuntu
65370
VSCode
21
Wolfi
288261
ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-2614
PyPI/lxml-html-clean
`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes
13 Jul
Fix available
Severity - 8.2 (High)
GHSA-4jhm-jv67-739f
PyPI/lxml-html-clean
`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes
08 Jul
Fix available
Severity - 8.2 (High)
PYSEC-2026-87
PyPI/lxml
See record for full details
24 Apr
Fix available
Severity - 7.5 (High)
GHSA-vfmq-68hx-4jfw
PyPI/lxml
lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files
21 Apr
Fix available
Severity - 7.5 (High)
PYSEC-2026-2202
PyPI/lxml-html-clean
See record for full details
05 Mar
Fix available
Severity - 6.1 (Medium)
PYSEC-2026-2201
PyPI/lxml-html-clean
See record for full details
05 Mar
Fix available
Severity - 6.1 (Medium)
GHSA-xvp8-3mhv-424c
PyPI/lxml-html-clean
lxml-html-clean has <base> tag injection through default Cleaner configuration
02 Mar
Fix available
Severity - 6.1 (Medium)
GHSA-hw26-mmpg-fqfg
PyPI/lxml-html-clean
lxml-html-clean has CSS @import Filter Bypass via Unicode Escapes
02 Mar
Fix available
Severity - 6.1 (Medium)
PYSEC-2024-160
PyPI/lxml-html-clean
github.com/fedora-python/lxml_html_clean
See record for full details
19 Nov 2024
Fix available
Severity - 6.1 (Medium)
GHSA-5jfw-gq64-q45f
PyPI/lxml-html-clean
HTML Cleaner allows crafted scripts in special contexts like svg or math to pass through
19 Nov 2024
Fix available
Severity - 7.7 (High)
GHSA-wrxv-2j5q-m38w
PyPI/lxml
lxml NULL Pointer Dereference allows attackers to cause a denial of service
06 Jul 2022
Fix available
Severity - 6.9 (Medium)
PYSEC-2022-230
PyPI/lxml
github.com/lxml/lxml
See record for full details
05 Jul 2022
Fix available
GHSA-57qw-cc2g-pv5p
PyPI/lxml
lxml Cross-site Scripting Via Control Characters
14 May 2022
Fix available
Severity - 5.3 (Medium)
GHSA-xp26-p53h-6h2p
PyPI/lxml
Improper Neutralization of Input During Web Page Generation in LXML
13 May 2022
Fix available
Severity - 5.3 (Medium)
PYSEC-2021-852
PyPI/lxml
github.com/lxml/lxml
github.com/lxml/lxml#diff-59130575b4fb2932c957db2922977d7d89afb0b2085357db1a14615a2fcad776
See record for full details
13 Dec 2021
Fix available
GHSA-55x5-fj6c-h6m8
PyPI/lxml
lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through
13 Dec 2021
Fix available
Severity - 6.3 (Medium)
Load more...
PyPI - OSV