lxml 4.2.5 released – security fix for HTML cleaner

Sept. 15, 2018
8:03 p.m.
Hi all, I released lxml 4.2.5 with an important bug fix for the HTML cleaner tool. It failed to remove JavaScript in encoded URLs. The documentation is here: https://lxml.de/ Download: https://pypi.python.org/pypi/lxml/4.2.5 Changelog: https://lxml.de/4.2/changes-4.2.5.html Github: https://github.com/lxml/lxml/releases/tag/lxml-4.2.5 This release was built using Cython 0.28.5. If you are interested in commercial support or customisations for the lxml package, please contact me directly. Have fun, Stefan 4.2.5 (2018-09-09) ================== Bugs fixed ---------- * Javascript URLs that used URL escaping were not removed by the HTML cleaner. Security problem found by Omar Eissa of Deloitte.
2353
Age (days ago)
2353
Last active (days ago)
0 comments
1 participants
participants (1)
-
Stefan Behnel