Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY3 SECURITY RECORDS

lxml

lxml

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-49825 20 Aug 2026 lxml: < 6.1.1; lxml html clean: < 0.4.5 Before applying this update, make sure all previously released errata relevant to your system have been applied. For detailed instructions how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_satellite/6.16/html/updating_red_hat_satellite/index Release Notes: Provisioning tokens are now required for all Operating System entries with Redhat family set. Attempts to download a unattended template without valid token will lead to “a provisioning token is required but a valid one was not provided” error. This changed behavior will lead to inability to use Generic or Subnet Bootdisks, systems using this bootdiks will be not matched with the host entry and not boot. To use Bootdisk after applying the errata, either use Full Host Bootdisk which uses tokens, or set Administer - Settings - Provisioning - Installation token lifetime to zero. This turns off the token enforcement and allows unauthenticated parties to use arbitrary MAC addresses in unattended requests to fetch provisioning kickstart with possibly sensitive data. Update reference ↗
CVE-2026-41066 24 Apr 2026 < 6.1.0 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2021-43818 13 Dec 2021 < 4.6.5 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.