openSUSE-SU-2026:20345-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20345-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:20345-1
Upstream
CVE (2)
Related
Published
2026-03-11T18:05:18Z
Modified
2026-03-13T08:57:17Z
Summary
Security update for python-lxml_html_clean
Details

This update for python-lxml_html_clean fixes the following issues:

Changes in python-lxml_html_clean:

  • CVE-2026-28348: improper keywords checking can allow external CSS loading (bsc#1259378)
  • CVE-2026-28350: lack of base tag handling can allow the hijacking of the resolution of relative URLs (bsc#1259379)
References

Affected packages

openSUSE:Leap 16.0 / python-lxml_html_clean

Package

Name
python-lxml_html_clean
Purl
pkg:rpm/opensuse/python-lxml_html_clean&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.4.2-bp160.2.1

Ecosystem specific

{
    "binaries":  [
        {
            "python313-lxml_html_clean":  "0.4.2-bp160.2.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20345-1.json"