Summary
Guillem Lefait discovered that lxml incorrectly handled certain URL attributes. A remote attacker could possibly use this issue to bypass URL sanitization, leading to a cross-site scripting attack. (CVE-2026-49825)
Qiu Sihao discovered that lxml incorrectly handled untrusted XML input. A remote attacker could possibly use this issue to read local files and expose sensitive information. This issue was only addressed in Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-41066)
Products covered
A separate affected-products list was not included in the collected bulletin.
Remediation
Separate remediation guidance was not included in the collected bulletin.
CVEs in this advisory 2
Updates
- Published by Ubuntu
The publication date reported by the vendor.
- Added to SecurityAlert
We collected the advisory from the official source.
- Confirmed at the source
Our collector saw this advisory during a later source check.