lxml-html-clean
PyPI4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting lxml-html-cleanpage 1 of 1
- CVE-2024-52595HIGHCVSS 7.7EG 7.7✓ Fixed in 0.4.02024-11-19
vulnerable: 0.1.0 ... 0.3.1 (7 versions)
lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.0, the HTML Parser in lxml does not properly handle context-switching for special HTML tags such as `<svg>`, `<math>` and `<…
- CVE-2026-28348MEDIUMCVSS 6.1EG 6.1✓ Fixed in 0.4.42026-03-05
vulnerable: 0.1.0 ... 0.4.3 (11 versions)
lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, the _has_sneaky_javascript() method strips backslashes before checking for dangerous CSS keywords. This causes CSS Unicod…
- CVE-2026-28350MEDIUMCVSS 6.1EG 6.1✓ Fixed in 0.4.42026-03-05
vulnerable: 0.1.0 ... 0.4.3 (11 versions)
lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, the <base> tag passes through the default Cleaner configuration. While page_structure=True removes html, head, and title …
- CVE-2026-49825HIGHCVSS 8.2EG 8.2✓ Fixed in 0.4.52026-07-08
vulnerable: 0.1.0 ... 0.4.4 (12 versions)
lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. conten…
Check whether lxml-html-clean is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for lxml-html-clean CVEs against the assets you own.
Start Free Scan →