lxml-html-clean
PyPI4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting lxml-html-cleanpage 1 of 1
- CVE-2024-52595HIGHCVSS 7.7EG 7.7fixed in 0.4.02024-11-19
vulnerable: 0.1.0 ... 0.3.1 (7 versions)
lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.0, the HTML Parser in lxml does not properly handle context-switching for special HTML tags such as `<svg>`, `<math>` and `<…
- CVE-2026-28348MEDIUMCVSS 6.1EG 6.1fixed in 0.4.42026-03-05
vulnerable: 0.1.0 ... 0.4.3 (11 versions)
lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, the _has_sneaky_javascript() method strips backslashes before checking for dangerous CSS keywords. This causes CSS Unicod…
- CVE-2026-28350MEDIUMCVSS 6.1EG 6.1fixed in 0.4.42026-03-05
vulnerable: 0.1.0 ... 0.4.3 (11 versions)
lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, the <base> tag passes through the default Cleaner configuration. While page_structure=True removes html, head, and title …
- CVE-2026-49825HIGHCVSS 8.2EG 8.2fixed in 0.4.52026-07-08
vulnerable: 0.1.0 ... 0.4.4 (12 versions)
lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. conten…
Check whether lxml-html-clean is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for lxml-html-clean CVEs against the assets you own.
Book a Demo →