CVE-2021-43818

Aliases:GHSA-55x5-fj6c-h6m8PYSEC-2021-852
Modified
Published: 13 Dec 2021, 18:05
Last modified:18 Dec 2025, 15:05

Vulnerability Summary

Overall Risk (default)
medium
34/100
CVSS Score
8.2 HIGH
v3.1 (cve.org)
EPSS Score
5.43% LOW
5% probability +1.67%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

13 Dec 2021, 18:05
Published
Vulnerability first disclosed
18 Dec 2025, 15:05
Last Modified
Vulnerability information updated

Description

lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5 to receive a patch. There are no known workarounds available.

CVSS Metrics

  • v4.0MEDIUMScore: 6.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:H/SA:N
  • v3.1HIGHScore: 8.2CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N
  • v3.1HIGHScore: 7.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
  • v2.0MEDIUMScore: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 5.43% Percentile: 90%

Techniques & Countermeasures

  • CWE-74Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

    The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

  • CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Affected Systems

  • debiandebian_linux

    9.0 | 10.0 | 11.0

  • fedoraprojectfedora

    34 | 35

  • lxmllxml

    < 4.6.5

  • netapphci_storage_node

    na

  • netappsolidfire

    na

  • netappsolidfire_enterprise_sds

    na

  • oraclecommunications_cloud_native_core_binding_support_function

    22.1.3

  • oraclecommunications_cloud_native_core_network_exposure_function

    22.1.1

  • oraclecommunications_cloud_native_core_policy

    22.2.0

  • oraclehttp_server

    12.2.1.3.0 | 12.2.1.4.0

  • oraclezfs_storage_appliance_kit

    8.8

  • PyPIlxml

    < 4.6.5 | < 12fa9669007180a7bb87d990c375cf91ca5b664a | < a3eacbc0dcf1de1c822ec29fb7d090a4b1712a9c

References (22)