Debian Package Tracker
Register | Log in
Subscribe

lxml-html-clean

blocklist-based HTML cleaner

Choose email to subscribe with

general
  • source: lxml-html-clean (main)
  • version: 0.4.4-1
  • maintainer: Matthias Klose (DMD)
  • arch: all
  • std-ver: 4.7.3
  • VCS: unknown
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • stable: 0.4.2-1
  • testing: 0.4.4-1
  • unstable: 0.4.4-1
versioned links
  • 0.4.2-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.4.4-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • python3-lxml-html-clean
action needed
lintian reports 1 warning normal
Lintian reports 1 warning about this package. You should make the package lintian clean getting rid of them.
Created: 2026-03-06 Last update: 2026-03-06 15:00
2 low-priority security issues in trixie low

There are 2 open security issues in trixie.

2 issues left for the package maintainer to handle:
  • CVE-2026-28348: (needs triaging) lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, the _has_sneaky_javascript() method strips backslashes before checking for dangerous CSS keywords. This causes CSS Unicode escape sequences to bypass the @import and expression() filters, allowing external CSS loading or XSS in older browsers. This issue has been patched in version 0.4.4.
  • CVE-2026-28350: (needs triaging) lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, the <base> tag passes through the default Cleaner configuration. While page_structure=True removes html, head, and title tags, there is no specific handling for <base>, allowing an attacker to inject it and hijack relative links on the page. This issue has been patched in version 0.4.4.

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-03-06 Last update: 2026-04-28 19:02
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.7.3).
Created: 2026-03-31 Last update: 2026-03-31 15:01
news
[rss feed]
  • [2026-03-11] lxml-html-clean 0.4.4-1 MIGRATED to testing (Debian testing watch)
  • [2026-03-06] Accepted lxml-html-clean 0.4.4-1 (source) into unstable (Matthias Klose)
  • [2025-10-10] lxml-html-clean 0.4.3-1 MIGRATED to testing (Debian testing watch)
  • [2025-10-05] Accepted lxml-html-clean 0.4.3-1 (source) into unstable (Matthias Klose)
  • [2025-05-03] lxml-html-clean 0.4.2-1 MIGRATED to testing (Debian testing watch)
  • [2025-04-23] Accepted lxml-html-clean 0.4.2-1 (source) into unstable (Matthias Klose)
  • [2024-11-23] lxml-html-clean 0.4.1-1 MIGRATED to testing (Debian testing watch)
  • [2024-11-18] Accepted lxml-html-clean 0.4.1-1 (source) into unstable (Matthias Klose)
  • [2024-10-30] lxml-html-clean 0.3.1-1 MIGRATED to testing (Debian testing watch)
  • [2024-10-24] Accepted lxml-html-clean 0.3.1-1 (source) into unstable (Matthias Klose)
  • [2024-09-14] lxml-html-clean 0.2.2-1 MIGRATED to testing (Debian testing watch)
  • [2024-09-09] Accepted lxml-html-clean 0.2.2-1 (source) into unstable (Matthias Klose)
  • [2024-09-04] lxml-html-clean 0.2.1-1 MIGRATED to testing (Debian testing watch)
  • [2024-08-30] Accepted lxml-html-clean 0.2.1-1 (source) into unstable (Matthias Klose)
  • [2024-08-07] lxml-html-clean 0.2.0-1 MIGRATED to testing (Debian testing watch)
  • [2024-08-02] Accepted lxml-html-clean 0.2.0-1 (source) into unstable (Matthias Klose)
  • [2024-04-20] lxml-html-clean 0.1.1-1 MIGRATED to testing (Debian testing watch)
  • [2024-04-15] Accepted lxml-html-clean 0.1.1-1 (source) into unstable (Matthias Klose)
  • [2024-04-08] Accepted lxml-html-clean 0.1.0-1 (source all) into unstable (Debian FTP Masters) (signed by: Matthias Klose)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian (0, 1)
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 0.4.4-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing