lxml vulnerabilities
CVEs whose affected-version data names the lxml package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-41066High· 7.5lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files
lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files
▾ Twilightlxml · lxmlEPSS 0.32%via OSV
CVE-2021-43818High· 8.2lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through
lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through
▾ Twilightlxml · lxmlEPSS 2.5%via OSV