DEBIAN-CVE-2021-43818

Source
https://security-tracker.debian.org/tracker/CVE-2021-43818
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-43818.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2021-43818
Upstream
Published
2021-12-13T18:15:08Z
Modified
2025-09-25T23:25:34.144365Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L CVSS Calculator
Summary
[none]
Details

lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5 to receive a patch. There are no known workarounds available.

References

Affected packages

Debian:11 / lxml

Package

Name
lxml
Purl
pkg:deb/debian/lxml?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.6.3+dfsg-0.1+deb11u1

Affected versions

4.*

4.6.3+dfsg-0.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / lxml

Package

Name
lxml
Purl
pkg:deb/debian/lxml?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.7.1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / lxml

Package

Name
lxml
Purl
pkg:deb/debian/lxml?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.7.1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14 / lxml

Package

Name
lxml
Purl
pkg:deb/debian/lxml?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.7.1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}