Re: [BLFS Trac] #23319: lxml-6.1.1 (Python module)
| Newsgroups | gmane.linux.lfs.beyond.book |
|---|---|
| Message-ID | <[email protected]> |
#23319: lxml-6.1.1 (Python module)
-------------------------+-------------------------------
Reporter: Bruce Dubbs | Owner: SecurityAdvisory
Type: enhancement | Status: new
Priority: elevated | Milestone: 13.1
Component: BOOK | Version: git
Severity: normal | Resolution:
Keywords: |
-------------------------+-------------------------------
Changes (by Joe Locash):
* owner: Joe Locash => SecurityAdvisory
* status: assigned => new
Comment:
{{{
6.1.1 (2026-05-18)
==================
Bugs fixed
----------
* The known link attributes in ``lxml.html.defs.link_attrs`` were missing
``xlink:href``,
which can be used for URL bypass attacks in embedded SVG/MathML/etc.
content.
https://github.com/fedora-python/lxml_html_clean/security/advisories
/GHSA-4jhm-jv67-739f
* The Linux wheels use a patched libxslt 1.1.43, fixing CVE-2025-7424 and
CVE-2025-11731.
* The Windows wheels use libxslt 1.1.45, fixing CVE-2025-7424 and
CVE-2025-11731.
}}}
Fixed at 8bd9c6df2b. Leaving open for SA.
--
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23319#comment:3>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch
--
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page