Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-7025.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-7025
Upstream
Published
2021-12-13T18:15:08Z
Modified
2026-04-01T05:21:42.721011Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L CVSS Calculator
Summary
CVE-2021-43818 affecting package python-lxml for versions less than 4.8.0-1
Details

lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5 to receive a patch. There are no known workarounds available.

References

Affected packages

Azure Linux:2 / python-lxml

Package

Name
python-lxml
Purl
pkg:rpm/azure-linux/python-lxml

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.8.0-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-7025.json"