{"api_version":"v1","generated_at":"2026-10-07T03:35:00+00:00","product":{"cve_count":3,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-lxml-lxml-52ead1984802","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"lxml","next_cursor":null,"observations":[{"affected":"lxml: < 6.1.1; lxml html clean: < 0.4.5","affected_versions_present":true,"cve_id":"CVE-2026-49825","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-49825","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For detailed instructions how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_satellite/6.16/html/updating_red_hat_satellite/index Release Notes: Provisioning tokens are now required for all Operating System entries with Redhat family set. Attempts to download a unattended template without valid token will lead to \u201ca provisioning token is required but a valid one was not provided\u201d error. This changed behavior will lead to inability to use Generic or Subnet Bootdisks, systems using this bootdiks will be not matched with the host entry and not boot. To use Bootdisk after applying the errata, either use Full Host Bootdisk which uses tokens, or set Administer - Settings - Provisioning - Installation token lifetime to zero. This turns off the token enforcement and allows unauthenticated parties to use arbitrary MAC addresses in unattended requests to fetch provisioning kickstart with possibly sensitive data.","last_modified":"2026-08-21T16:41:54.849Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-49825","primary_source":"","published":"2026-08-20T14:42:30.748Z"},{"affected":"< 6.1.0","affected_versions_present":true,"cve_id":"CVE-2026-41066","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41066","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-24T18:04:04.548Z","patch_url":"https://github.com/lxml/lxml/security/advisories/GHSA-vfmq-68hx-4jfw","primary_source":"","published":"2026-04-24T16:45:19.617Z"},{"affected":"< 4.6.5","affected_versions_present":true,"cve_id":"CVE-2021-43818","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-43818","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-12-18T15:05:59.477Z","patch_url":"https://github.com/lxml/lxml/commit/12fa9669007180a7bb87d990c375cf91ca5b664a","primary_source":"","published":"2021-12-13T18:05:12.000Z"}],"source_generated_at":"2026-10-06T06:22:27.870Z","vendor":"lxml"}}
