[ALSA-2026:66204] Important: python-lxml security update
Type:
security
Severity:
important
Release date:
2026-09-10
Description:
Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Security Fix(es): * lxml: lxml-html-clean: lxml: URL bypass vulnerability in Cleaner via missing xlink:href (CVE-2026-49825) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 python3-lxml-4.6.5-3.el9_8.1.aarch64.rpm 1f948a2eab3eedb636d889c0de03b048d053111b134254c82a805964d1f8695f
ppc64le python3-lxml-4.6.5-3.el9_8.1.ppc64le.rpm 54fb78f7f4012a90c2a19d02bee60ad8f7df2d1fe3213d15905717fd6c4f3963
s390x python3-lxml-4.6.5-3.el9_8.1.s390x.rpm f06a3df5ce90a817cd2b74851d72ca428f2b910376d3618af4c8c9fb513de33c
x86_64 python3-lxml-4.6.5-3.el9_8.1.x86_64.rpm 4beb075a36ba7e0097af88942d486c1bd3fdcfa576a686d298bee4ca483e1352
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.