[Git][security-tracker-team/security-tracker][master] Update status for CVE-2026-49825

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Sep 14 06:47:26 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c9d553a5 by Salvatore Bonaccorso at 2026-09-14T07:33:05+02:00
Update status for CVE-2026-49825

The tracking is still not fully correct. The lxml-html-clean after the
split just required a bumped dependency on lxml but is not a source fix,
but still to make CVE-2026-49825 both parts will be required.

Keep for now the dual tracking or eventually just associate it with
src:lxml.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -25380,12 +25380,13 @@ CVE-2026-53424 (Authentication Bypass by Capture-replay vulnerability in dropbox
 CVE-2026-49996 (SecureDrop Client is a desktop app for journalists to securely communi ...)
 	NOT-FOR-US: SecureDrop Client
 CVE-2026-49825 (lxml is a library for processing XML and HTML in the Python language.  ...)
-	- lxml <unfixed>
+	- lxml 6.1.3-1
 	[trixie] - lxml <no-dsa> (Minor issue)
-	- lxml-html-clean <unfixed>
+	- lxml-html-clean 0.4.5-1
 	[trixie] - lxml-html-clean <no-dsa> (Minor issue)
 	NOTE: https://github.com/fedora-python/lxml_html_clean/security/advisories/GHSA-4jhm-jv67-739f
 	NOTE: Fixed by: https://github.com/lxml/lxml/commit/5927a6d5e851845140975d99b65461e255caaab0 (lxml-6.1.1)
+	NOTE: Fixed by: https://github.com/fedora-python/lxml_html_clean/commit/322357ac61c6cf80fcbaba53b4e92e31f3ded9f2 (0.4.5)
 	NOTE: lxml-html-clean was split out of lxml in 5.2.0
 	NOTE: Code fix in src:lxml, lxml-html-clean will require bumped dependency on lxml >= 6.1.1
 CVE-2026-46537



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c9d553a55659642d35b848e19385f5170a71e6bb

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c9d553a55659642d35b848e19385f5170a71e6bb
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260914/0cddc95c/attachment.htm>


More information about the debian-security-tracker-commits mailing list