Re: [BLFS Trac] #23319: lxml-6.1.1 (Python module)

"BLFS Trac" ([email protected] via blfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.beyond.book
Message-ID <[email protected]>
#23319: lxml-6.1.1 (Python module)
-------------------------+-------------------------------
 Reporter:  Bruce Dubbs  |       Owner:  SecurityAdvisory
     Type:  enhancement  |      Status:  new
 Priority:  elevated     |   Milestone:  13.1
Component:  BOOK         |     Version:  git
 Severity:  normal       |  Resolution:
 Keywords:               |
-------------------------+-------------------------------
Changes (by Joe Locash):

 * owner:  Joe Locash => SecurityAdvisory
 * status:  assigned => new

Comment:

 {{{
 6.1.1 (2026-05-18)

 ==================

 Bugs fixed
 ----------

 * The known link attributes in ``lxml.html.defs.link_attrs`` were missing
 ``xlink:href``,
   which can be used for URL bypass attacks in embedded SVG/MathML/etc.
 content.
   https://github.com/fedora-python/lxml_html_clean/security/advisories
 /GHSA-4jhm-jv67-739f

 * The Linux wheels use a patched libxslt 1.1.43, fixing CVE-2025-7424 and
 CVE-2025-11731.

 * The Windows wheels use libxslt 1.1.45, fixing CVE-2025-7424 and
 CVE-2025-11731.
 }}}
 Fixed at 8bd9c6df2b. Leaving open for SA.
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23319#comment:3>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.