Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

openSUSE Leap 16.0 python-lxml-html-clean Moderate CSS Load Risk 20345-1

opensuse
Calendar Grey March 12, 2026
Dist Opensuse Esm H88
The openSUSE security update resolves two vulnerabilities in python-lxml_html_clean, enhancing system integrity. Discover details.
An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.

Description

This update for python-lxml_html_clean fixes the following issues:

Changes in python-lxml_html_clean:

- CVE-2026-28348: improper keywords checking can allow external CSS loading (bsc#1259378)

- CVE-2026-28350: lack of base tag handling can allow the hijacking of the resolution of relative URLs (bsc#1259379)

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-packagehub-157=1

Patch

Package List

- openSUSE Leap 16.0:

python313-lxml_html_clean-0.4.2-bp160.2.1

References

* bsc#1259378

* bsc#1259379

References:

* https://www.suse.com/security/cve/CVE-2026-28348.html

* https://www.suse.com/security/cve/CVE-2026-28350.html

Announcement ID: openSUSE-SU-2026:20345-1
Rating: moderate
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here