ELSA-2026-67943

ELSA-2026-67943 - python-lxml security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2026-09-18

Description


[4.2.3-5]
- Security fix for CVE-2026-49825: missing xlink:href in known HTML
link attributes
Resolves: RHEL-251508

[4.2.3-4]
- Security fix for CVE-2021-43818
Resolves: rhbz#2032569

[4.2.3-3]
- Security fix for CVE-2021-28957
Resolves: rhbz#1941534

[4.2.3-2]
- Security fix for CVE-2020-27783: mXSS due to the use of improper parser
Resolves: rhbz#1901633

[4.2.3-1]
- New upstream release 4.2.3

[4.1.1-3]
- Conditionalize the python2 subpackage

[4.1.1-2]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild

[4.1.1-1]
- Update to 4.1.1

[4.0.0-2]
- Conditionally allow building without Cython

[4.0.0-1]
- Update to 4.0.0


Related CVEs


CVE-2026-49825

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) python-lxml-4.2.3-5.el8_10.src.rpm227e51781d6e371acf7dac6c319dd8931a983f5ef00ef9a41d625939cf67f125-ol8_aarch64_appstream
python3-lxml-4.2.3-5.el8_10.aarch64.rpm2a5405f61f6e87d308200ed532c75ed67ad6f3fadcf4c4afe48f3e22349b1420-ol8_aarch64_appstream
Oracle Linux 8 (x86_64) python-lxml-4.2.3-5.el8_10.src.rpm227e51781d6e371acf7dac6c319dd8931a983f5ef00ef9a41d625939cf67f125-ol8_x86_64_appstream
python3-lxml-4.2.3-5.el8_10.x86_64.rpm57646d5c2e25dcc593bf45aa46bf79ebe25967af13be0041fa7e51e0a9712391-ol8_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete