Opened 6 months ago

Closed 5 months ago

#23162 closed enhancement (fixed)

lxml-6.1.0 (Python module)

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: elevated Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New minor version.

Change History (3)

comment:1 by Joe Locash, 6 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:2 by Joe Locash, 6 months ago

Owner: changed from Joe Locash to SecurityAdvisory
Priority: normal → elevated
Status: assigned → new
6.1.0 (2026-04-17)
==================

This release fixes a possible external entity injection (XXE) vulnerability in
``iterparse()`` and the ``ETCompatXMLParser``.

Features added
--------------

* GH#486: The HTML ARIA accessibility attributes were added to the set of safe attributes
  in ``lxml.html.defs``.  This allows ``lxml_html_clean`` to pass them through.
  Patch by oomsveta.

* The default chunk size for reading from file-likes in ``iterparse()`` is now configurable
  with a new ``chunk_size`` argument.

Bugs fixed
----------

* LP#2146291: The ``resolve_entities`` option was still set to ``True`` for
  ``iterparse`` and ``ETCompatXMLParser``, allowing for external entity injection (XXE)
  when using these parsers without setting this option explicitly.
  The default was now changed to ``'internal'`` only (as for the normal XML and HTML parsers
  since lxml 5.0).
  Issue found by Sihao Qiu as CVE-2026-41066.

Fixed at 10b247d05e. Leaving open for SA.

comment:3 by Douglas R. Reno, 5 months ago

Resolution: → fixed
Status: new → closed

SA-13.0-058 issued.

Note: See TracTickets for help on using tickets.