CVE-2021-43818
published 2021-12-13CVE-2021-43818: lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content…
PriorityP334high7.1CVSS 3.1
AVNACLPRNUIRSCCLILAL
EPSS
2.46%
82.7th percentile
lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5 to receive a patch. There are no known workarounds available.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | lxml | < lxml 4.7.1-1 (bookworm) | lxml 4.7.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| lxml | lxml | < 4.6.5 | 4.6.5 |
| lxml | lxml | >= 0 < 4.6.3+dfsg-0.1+deb11u1 | 4.6.3+dfsg-0.1+deb11u1 |
| lxml | lxml | >= 0 < 4.7.1-1 | 4.7.1-1 |
| lxml | lxml | >= 0 < 4.7.1-1 | 4.7.1-1 |
| lxml | lxml | >= 0 < 4.7.1-1 | 4.7.1-1 |
| lxml | lxml | >= 0 < 4.6.5 | 4.6.5 |
| msrc | cbl2_python-lxml_4.8.0-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_python-lxml_4.7.1-1_on_cbl_mariner_1.0 | — | — |
| oracle | communications_cloud_native_core_binding_support_function | — | — |
| oracle | communications_cloud_native_core_network_exposure_function | — | — |
| oracle | communications_cloud_native_core_policy | — | — |
| oracle | http_server | — | — |
| oracle | http_server | — | — |
| oracle | zfs_storage_appliance_kit | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.1HIGH
vendor_debian8.2HIGH
vendor_redhat8.2HIGH
vendor_msrc7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
lxml vulnerability
vendor_ubuntu·2022-01-12
CVE-2021-43818 lxml vulnerability
Title: lxml vulnerability
Summary: lxml could be made to execute arbitrary code if it received a specially crafted XML
or HTML file.
It was discovered that lxml incorrectly handled certain XML and HTML files.
An attacker could possibly use this issue to execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
HTML Cleaner allows crafted and SVG embedded scripts to pass through
vendor_msrc·2021-12-14·CVSS 7.1
CVE-2021-43818 [HIGH] CWE-74 HTML Cleaner allows crafted and SVG embedded scripts to pass through
HTML Cleaner allows crafted and SVG embedded scripts to pass through
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Refer
Red Hat
python-lxml: HTML Cleaner allows crafted and SVG embedded scripts to pass through
vendor_redhat·2021-12-12·CVSS 8.2
CVE-2021-43818 [HIGH] CWE-79 python-lxml: HTML Cleaner allows crafted and SVG embedded scripts to pass through
python-lxml: HTML Cleaner allows crafted and SVG embedded scripts to pass through
lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5 to receive a patch. There are no known workarounds available.
There's a flaw in python-lxml's HTML Cleaner component, which is responsible for sanitizing HTML and Javascript. An attacker who is able to submit a crafted payload to a web service using python-lxml's HTML Cleaner may be able to trigger script execution in clients such as web browsers. This can occur because the HTML
Debian
CVE-2021-43818: lxml - lxml is a library for processing XML and HTML in the Python language. Prior to v...
vendor_debian·2021·CVSS 8.2
CVE-2021-43818 [HIGH] CVE-2021-43818: lxml - lxml is a library for processing XML and HTML in the Python language. Prior to v...
lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5 to receive a patch. There are no known workarounds available.
Scope: local
bookworm: resolved (fixed in 4.7.1-1)
bullseye: resolved (fixed in 4.6.3+dfsg-0.1+deb11u1)
forky: resolved (fixed in 4.7.1-1)
sid: resolved (fixed in 4.7.1-1)
trixie: resolved (fixed in 4.7.1-1)
OSV
CVE-2021-43818: lxml is a library for processing XML and HTML in the Python language
osv·2021-12-13·CVSS 7.1
CVE-2021-43818 [HIGH] CVE-2021-43818: lxml is a library for processing XML and HTML in the Python language
lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5 to receive a patch. There are no known workarounds available.
GHSA
lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through
ghsa·2021-12-13
CVE-2021-43818 [MEDIUM] CWE-74 lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through
lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through
### Impact
The HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs.
Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5.
### Patches
The issue has been resolved in lxml 4.6.5.
### Workarounds
None.
### References
The issues are tracked under the report IDs GHSL-2021-1037 and GHSL-2021-1038.
OSV
lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through
osv·2021-12-13
CVE-2021-43818 [MEDIUM] lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through
lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through
### Impact
The HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs.
Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5.
### Patches
The issue has been resolved in lxml 4.6.5.
### Workarounds
None.
### References
The issues are tracked under the report IDs GHSL-2021-1037 and GHSL-2021-1038.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/lxml/lxml/commit/12fa9669007180a7bb87d990c375cf91ca5b664ahttps://github.com/lxml/lxml/commit/a3eacbc0dcf1de1c822ec29fb7d090a4b1712a9c#diff-59130575b4fb2932c957db2922977d7d89afb0b2085357db1a14615a2fcad776https://github.com/lxml/lxml/commit/f2330237440df7e8f39c3ad1b1aa8852be3b27c0https://github.com/lxml/lxml/security/advisories/GHSA-55x5-fj6c-h6m8https://lists.debian.org/debian-lts-announce/2021/12/msg00037.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TUIS2KE3HZ2AAQKXFLTJFZPP2IFHJTC7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V2XMOM5PFT6U5AAXY6EFNT5JZCKKHK2V/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WZGNET2A4WGLSUXLBFYKNC5PXHQMI3I7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZQ4SPKJX3RRJK4UWA6FXCRHD2TVRQI44/https://security.gentoo.org/glsa/202208-06https://security.netapp.com/advisory/ntap-20220107-0005/https://www.debian.org/security/2022/dsa-5043https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://github.com/lxml/lxml/commit/12fa9669007180a7bb87d990c375cf91ca5b664ahttps://github.com/lxml/lxml/commit/a3eacbc0dcf1de1c822ec29fb7d090a4b1712a9c#diff-59130575b4fb2932c957db2922977d7d89afb0b2085357db1a14615a2fcad776https://github.com/lxml/lxml/commit/f2330237440df7e8f39c3ad1b1aa8852be3b27c0https://github.com/lxml/lxml/security/advisories/GHSA-55x5-fj6c-h6m8https://lists.debian.org/debian-lts-announce/2021/12/msg00037.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TUIS2KE3HZ2AAQKXFLTJFZPP2IFHJTC7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V2XMOM5PFT6U5AAXY6EFNT5JZCKKHK2V/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WZGNET2A4WGLSUXLBFYKNC5PXHQMI3I7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZQ4SPKJX3RRJK4UWA6FXCRHD2TVRQI44/https://security.gentoo.org/glsa/202208-06https://security.netapp.com/advisory/ntap-20220107-0005/https://www.debian.org/security/2022/dsa-5043https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.html
2021-12-13
Published