Opened 4 months ago
Closed 4 months ago
#23319 closed enhancement (fixed)
lxml-6.1.1 (Python module)
| Reported by: | Bruce Dubbs | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | elevated | Milestone: | 13.1 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version.
Change History (4)
comment:1 by , 4 months ago
| Priority: | normal → elevated |
|---|
comment:2 by , 4 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:3 by , 4 months ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
6.1.1 (2026-05-18) ================== Bugs fixed ---------- * The known link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. https://github.com/fedora-python/lxml_html_clean/security/advisories/GHSA-4jhm-jv67-739f * The Linux wheels use a patched libxslt 1.1.43, fixing CVE-2025-7424 and CVE-2025-11731. * The Windows wheels use libxslt 1.1.45, fixing CVE-2025-7424 and CVE-2025-11731.
Fixed at 8bd9c6df2b. Leaving open for SA.
Note:
See TracTickets
for help on using tickets.

This release fixes a vulnerability that can allow for URL bypass attacks. Details not available at the expected location yet though, probably still embargoed.