USN-8897-1: lxml vulnerabilities
Guillem Lefait discovered that lxml incorrectly handled certain URL
attributes. A remote attacker could possibly use this issue to bypass
URL sanitization, leading to a cross-site scripting attack.
(CVE-2026-49825)
Qiu Sihao discovered that lxml incorrectly handled untrusted XML input.
A remote attacker could possibly use this issue to read local files and
expose sensitive information. This issue was only addressed in Ubuntu 24.04
LTS and Ubuntu 26.04 LTS. (CVE-2026-41066)