CVE-2026-28348

EUVD-2026-9868
lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, the _has_sneaky_javascript() method strips backslashes before checking for dangerous CSS keywords. This causes CSS Unicode escape sequences to bypass the @import and expression() filters, allowing external CSS loading or XSS in older browsers. This issue has been patched in version 0.4.4.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 13.43%
Affected Products (NVD)
VendorProductVersion
fedoralovespythonlxml_html_clean
𝑥
< 0.4.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
lxml
bookworm
vulnerable
forky
6.1.0-1
fixed
sid
6.1.0-1
fixed
trixie
5.4.0-1
fixed
lxml-html-clean
forky
0.4.5-1
fixed
sid
0.4.5-1
fixed
trixie
0.4.4-1~deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
lxml-html-clean
jammy
dne
noble
needs-triage
questing
ignored
resolute
needs-triage