ELSA-2026-67943 - python-lxml security update
| Type: | SECURITY |
| Impact: | IMPORTANT |
| Release Date: | 2026-09-18 |
Description
[4.2.3-5]
- Security fix for CVE-2026-49825: missing xlink:href in known HTML
link attributes
Resolves: RHEL-251508
[4.2.3-4]
- Security fix for CVE-2021-43818
Resolves: rhbz#2032569
[4.2.3-3]
- Security fix for CVE-2021-28957
Resolves: rhbz#1941534
[4.2.3-2]
- Security fix for CVE-2020-27783: mXSS due to the use of improper parser
Resolves: rhbz#1901633
[4.2.3-1]
- New upstream release 4.2.3
[4.1.1-3]
- Conditionalize the python2 subpackage
[4.1.1-2]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild
[4.1.1-1]
- Update to 4.1.1
[4.0.0-2]
- Conditionally allow building without Cython
[4.0.0-1]
- Update to 4.0.0
Related CVEs
Updated Packages
| Release/Architecture | Filename | sha256 | Superseded By Advisory | Channel Label |
|
| Oracle Linux 8 (aarch64) | python-lxml-4.2.3-5.el8_10.src.rpm | 227e51781d6e371acf7dac6c319dd8931a983f5ef00ef9a41d625939cf67f125 | - | ol8_aarch64_appstream |
| python3-lxml-4.2.3-5.el8_10.aarch64.rpm | 2a5405f61f6e87d308200ed532c75ed67ad6f3fadcf4c4afe48f3e22349b1420 | - | ol8_aarch64_appstream |
|
| Oracle Linux 8 (x86_64) | python-lxml-4.2.3-5.el8_10.src.rpm | 227e51781d6e371acf7dac6c319dd8931a983f5ef00ef9a41d625939cf67f125 | - | ol8_x86_64_appstream |
| python3-lxml-4.2.3-5.el8_10.x86_64.rpm | 57646d5c2e25dcc593bf45aa46bf79ebe25967af13be0041fa7e51e0a9712391 | - | ol8_x86_64_appstream |
This page is generated automatically and has not been checked for errors or omissions. For clarification
or corrections please contact the Oracle Linux ULN team