CVE-2021-28957
published 2021-03-21CVE-2021-28957: An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner…
PriorityP433medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
4.00%
89.4th percentile
An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner class does not remove the formaction attribute allowing for JS to bypass the sanitizer. A remote attacker could exploit this flaw to run arbitrary JS code on users who interact with incorrectly sanitized HTML. This issue is patched in lxml 4.6.3.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | lxml | < lxml 4.6.3-1 (bookworm) | lxml 4.6.3-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| lxml | lxml | < 4.6.3 | 4.6.3 |
| lxml | lxml | >= 0 < 4.6.3-1 | 4.6.3-1 |
| lxml | lxml | >= 0 < 4.6.3-1 | 4.6.3-1 |
| lxml | lxml | >= 0 < 4.6.3-1 | 4.6.3-1 |
| lxml | lxml | >= 0 < 4.6.3-1 | 4.6.3-1 |
| lxml | lxml | >= 0 < 4.6.3 | 4.6.3 |
| msrc | cbl2_python-lxml_4.8.0-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_python-lxml_4.6.3-1_on_cbl_mariner_1.0 | — | — |
| oracle | zfs_storage_appliance_kit | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
ghsa6.1MEDIUM
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_msrc6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
lxml vulnerability
vendor_ubuntu·2021-04-08
CVE-2021-28957 lxml vulnerability
Title: lxml vulnerability
Summary: lxml could allow cross-site scripting (XSS) attacks.
USN-4896-1 fixed a vulnerability in lxml. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that lxml incorrectly handled certain HTML attributes. A
remote attacker could possibly use this issue to perform cross-site
scripting (XSS) attacks.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
lxml vulnerability
vendor_ubuntu·2021-03-30
CVE-2021-28957 lxml vulnerability
Title: lxml vulnerability
Summary: lxml could allow cross-site scripting (XSS) attacks.
It was discovered that lxml incorrectly handled certain HTML attributes. A
remote attacker could possibly use this issue to perform cross-site
scripting (XSS) attacks.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
python-lxml: Missing input sanitization for formaction HTML5 attributes may lead to XSS
vendor_redhat·2021-03-21·CVSS 6.1
CVE-2021-28957 [MEDIUM] CWE-79 python-lxml: Missing input sanitization for formaction HTML5 attributes may lead to XSS
python-lxml: Missing input sanitization for formaction HTML5 attributes may lead to XSS
An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner class does not remove the formaction attribute allowing for JS to bypass the sanitizer. A remote attacker could exploit this flaw to run arbitrary JS code on users who interact with incorrectly sanitized HTML. This issue is patched in lxml 4.6.3.
A flaw was found in python-lxml. The HTML5 formaction attribute is not input sanitized like the HTML action attribute is which can lead to a Cross-Site Scripting attack (XSS) when an application uses python-lxml to sanitize user inputs. The highest threat from this vulnerability is to data confidentiality
Microsoft
An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments the Cleaner class does not remove the formaction attribu
vendor_msrc·2021-03-09·CVSS 6.1
CVE-2021-28957 [MEDIUM] CWE-79 An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments the Cleaner class does not remove the formaction attribu
An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments the Cleaner class does not remove the formaction attribute allowing for JS to bypass the sanitizer. A remote attacker could exploit this flaw to run arbitrary JS code on users who interact with incorrectly sanitized HTML. This issue is patched in lxml 4.6.3.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is com
Debian
CVE-2021-28957: lxml - An XSS vulnerability was discovered in python-lxml's clean module versions befor...
vendor_debian·2021·CVSS 6.1
CVE-2021-28957 [MEDIUM] CVE-2021-28957: lxml - An XSS vulnerability was discovered in python-lxml's clean module versions befor...
An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner class does not remove the formaction attribute allowing for JS to bypass the sanitizer. A remote attacker could exploit this flaw to run arbitrary JS code on users who interact with incorrectly sanitized HTML. This issue is patched in lxml 4.6.3.
Scope: local
bookworm: resolved (fixed in 4.6.3-1)
bullseye: resolved (fixed in 4.6.3-1)
forky: resolved (fixed in 4.6.3-1)
sid: resolved (fixed in 4.6.3-1)
trixie: resolved (fixed in 4.6.3-1)
GHSA
`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes
ghsa·2026-07-08·CVSS 6.1
CVE-2026-49825 [MEDIUM] CWE-184 `lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes
`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes
# `lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes (`xlink:href`)
**Reporter:** Guillem Lefait · **Date:** 2026-05-10
**Affected:** `lxml` ≤ 6.1.0 and `lxml_html_clean` ≤ 0.4.4 (latest stable)
**Confirmed against:** lxml 6.1.0 + lxml_html_clean 0.4.4 on Python 3.13.5, 3.14.4, and 3.15.0a8 (libxml2 2.14.6 / 2.9.14 — bug is in pure-Python sanitizer logic, independent of the libxml2 backend)
**Root-cause class:** same as CVE-2021-28957 (`formaction` missing from `link_attrs`)
## Summary
`Cleaner` filters URL schemes (`javascript:`, `vbscript:`, …) by walking links via `rewrite_links()`, which delegates to `iterlinks()`, which only yields attributes named in
GHSA
lxml vulnerable to Cross-Site Scripting
ghsa·2021-03-22
CVE-2021-28957 [MEDIUM] CWE-79 lxml vulnerable to Cross-Site Scripting
lxml vulnerable to Cross-Site Scripting
An XSS vulnerability was discovered in the python `lxml` clean module versions before 4.6.3. When disabling `the safe_attrs_only` and `forms` arguments, the `Cleaner` class does not remove the `formaction` attribute allowing for JS to bypass the sanitizer. A remote attacker could exploit this flaw to run arbitrary JS code on users who interact with incorrectly sanitized HTML. This issue is patched in `lxml` 4.6.3.
OSV
lxml vulnerable to Cross-Site Scripting
osv·2021-03-22
CVE-2021-28957 [MEDIUM] lxml vulnerable to Cross-Site Scripting
lxml vulnerable to Cross-Site Scripting
An XSS vulnerability was discovered in the python `lxml` clean module versions before 4.6.3. When disabling `the safe_attrs_only` and `forms` arguments, the `Cleaner` class does not remove the `formaction` attribute allowing for JS to bypass the sanitizer. A remote attacker could exploit this flaw to run arbitrary JS code on users who interact with incorrectly sanitized HTML. This issue is patched in `lxml` 4.6.3.
OSV
CVE-2021-28957: An XSS vulnerability was discovered in python-lxml's clean module versions before 4
osv·2021-03-21·CVSS 6.1
CVE-2021-28957 [MEDIUM] CVE-2021-28957: An XSS vulnerability was discovered in python-lxml's clean module versions before 4
An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner class does not remove the formaction attribute allowing for JS to bypass the sanitizer. A remote attacker could exploit this flaw to run arbitrary JS code on users who interact with incorrectly sanitized HTML. This issue is patched in lxml 4.6.3.
No detection rules found.
No public exploits indexed.
https://bugs.launchpad.net/lxml/+bug/1888153https://github.com/lxml/lxml/commit/a5f9cb52079dc57477c460dbe6ba0f775e14a999https://github.com/lxml/lxml/pull/316/commits/10ec1b4e9f93713513a3264ed6158af22492f270https://lists.debian.org/debian-lts-announce/2021/03/msg00031.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3C2R44VDUY7FJVMAVRZ2WY7XYL4SVN45/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XXN3QPWCTQVOGW4BMWV3AUUZZ4NRZNSQ/https://security.gentoo.org/glsa/202208-06https://security.netapp.com/advisory/ntap-20210521-0004/https://www.debian.org/security/2021/dsa-4880https://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://bugs.launchpad.net/lxml/+bug/1888153https://github.com/lxml/lxml/commit/a5f9cb52079dc57477c460dbe6ba0f775e14a999https://github.com/lxml/lxml/pull/316/commits/10ec1b4e9f93713513a3264ed6158af22492f270https://lists.debian.org/debian-lts-announce/2021/03/msg00031.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3C2R44VDUY7FJVMAVRZ2WY7XYL4SVN45/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XXN3QPWCTQVOGW4BMWV3AUUZZ4NRZNSQ/https://security.gentoo.org/glsa/202208-06https://security.netapp.com/advisory/ntap-20210521-0004/https://www.debian.org/security/2021/dsa-4880https://www.oracle.com/security-alerts/cpuoct2021.html
2021-03-21
Published