Opened 4 months ago

Closed 4 months ago

#23319 closed enhancement (fixed)

lxml-6.1.1 (Python module)

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: elevated Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (4)

comment:1 by Douglas R. Reno, 4 months ago

Priority: normal → elevated

This release fixes a vulnerability that can allow for URL bypass attacks. Details not available at the expected location yet though, probably still embargoed.

comment:2 by Joe Locash, 4 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:3 by Joe Locash, 4 months ago

Owner: changed from Joe Locash to SecurityAdvisory
Status: assigned → new
6.1.1 (2026-05-18)

==================

Bugs fixed
----------

* The known link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``,
  which can be used for URL bypass attacks in embedded SVG/MathML/etc. content.
  https://github.com/fedora-python/lxml_html_clean/security/advisories/GHSA-4jhm-jv67-739f

* The Linux wheels use a patched libxslt 1.1.43, fixing CVE-2025-7424 and CVE-2025-11731.

* The Windows wheels use libxslt 1.1.45, fixing CVE-2025-7424 and CVE-2025-11731.

Fixed at 8bd9c6df2b. Leaving open for SA.

comment:4 by Douglas R. Reno, 4 months ago

Resolution: → fixed
Status: new → closed

SA-13.0-095 issued

Note: See TracTickets for help on using tickets.