lxml (4.5.0-1ubuntu0.5) focal-security; urgency=medium * SECURITY UPDATE: XSS vulnerability - debian/patches/CVE-2021-43818-*.patch: prevent "@import" from re-occurring in the CSS after replacements and remove SVG image data URLs since they can embed script content in src/lxml/html/clean.py, src/html/tests/test_clean.py. - CVE-2021-43818 -- Leonidas Da Silva Barbosa Tue, 04 Jan 2022 09:33:10 -0300 lxml (4.5.0-1ubuntu0.3) focal-security; urgency=medium * SECURITY UPDATE: incorrect formaction attribute input sanitization - debian/patches/CVE-2021-28957.patch: add HTML-5 formaction attribute to defs.link_attrs in src/lxml/html/defs.py, src/lxml/html/tests/test_clean.py. - CVE-2021-28957 -- Marc Deslauriers Mon, 29 Mar 2021 12:04:02 -0400 lxml (4.5.0-1ubuntu0.2) focal-security; urgency=medium * SECURITY UPDATE: XSS vulnerability - debian/patches/CVE-2020-27783-part2*.patch: This adds the missing part reported from upstream Prevent combinations of