Back to vendor advisories
Ubuntu Security NoticesUSN-8897-1

USN-8897-1: lxml vulnerabilities

Severity not listed 2 CVEs Published Oct 7, 2026 at 4:13 PM UTC

Summary

Guillem Lefait discovered that lxml incorrectly handled certain URL attributes. A remote attacker could possibly use this issue to bypass URL sanitization, leading to a cross-site scripting attack. (CVE-2026-49825)

Qiu Sihao discovered that lxml incorrectly handled untrusted XML input. A remote attacker could possibly use this issue to read local files and expose sensitive information. This issue was only addressed in Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-41066)

Products covered

A separate affected-products list was not included in the collected bulletin.

Remediation

Separate remediation guidance was not included in the collected bulletin.

CVEs in this advisory 2

Updates

  1. Published by Ubuntu

    The publication date reported by the vendor.

  2. Added to SecurityAlert

    We collected the advisory from the official source.

  3. Confirmed at the source

    Our collector saw this advisory during a later source check.