CVE-2026-28350

EUVD-2026-20098
lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, the <base> tag passes through the default Cleaner configuration. While page_structure=True removes html, head, and title tags, there is no specific handling for <base>, allowing an attacker to inject it and hijack relative links on the page. This issue has been patched in version 0.4.4.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 16.69%
Affected Products (NVD)
VendorProductVersion
fedoralovespythonlxml_html_clean
𝑥
< 0.4.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
lxml
bookworm
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
6.1.0-1
fixed
sid
6.1.0-1
fixed
trixie
5.4.0-1
fixed
lxml-html-clean
forky
0.4.5-1
fixed
sid
0.4.5-1
fixed
trixie
0.4.4-1~deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
lxml-html-clean
jammy
dne
noble
needs-triage
questing
ignored
resolute
needs-triage