© 2025-2026 PySpect
First version without a known vulnerability: 6.1.0
lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files
Fixed in: 6.1.0
lxml NULL Pointer Dereference allows attackers to cause a denial of service
Fixed in: 4.9.1, 86368e9cf70a0ad23cccd5ee32de847149af0c6f
lxml Cross-site Scripting Via Control Characters
Fixed in: 3.3.5
Improper Neutralization of Input During Web Page Generation in LXML
Fixed in: 4.2.5, 6be1d081b49c97cfd7b3fbd934a193b668629109
lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through
Fixed in: 4.6.5, f2330237440df7e8f39c3ad1b1aa8852be3b27c0, 12fa9669007180a7bb87d990c375cf91ca5b664a, a3eacbc0dcf1de1c822ec29fb7d090a4b1712a9c
lxml vulnerable to Cross-Site Scripting
Fixed in: 4.6.3, a5f9cb52079dc57477c460dbe6ba0f775e14a999
lxml vulnerable to Cross-site Scripting
Fixed in: 4.6.2