HTML Cleaning Functionality in lxml_html_clean Affected by Tag Hijacking
CVE-2026-28350
What is CVE-2026-28350?
The lxml_html_clean library, designed for HTML cleaning functionalities, has a significant flaw where the tag is not properly handled in the default Cleaner configuration. This oversight allows attackers to inject malicious tags, enabling them to hijack relative links within web pages. The issue was present in versions prior to 0.4.4 and can undermine the security of applications relying on this library for safe HTML processing. It is crucial for developers to upgrade to version 0.4.4 or later to mitigate this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
lxml_html_clean < 0.4.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
