Security: lxml/lxml
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local filesGHSA-vfmq-68hx-4jfw published
Apr 18, 2026 by scoderHigh -
HTML Cleaner allows crafted and SVG embedded scripts to pass throughGHSA-55x5-fj6c-h6m8 published
Dec 12, 2021 by scoderModerate