CVE-2020-27783: Debian Linux

Medium severity, CVSS 6.1. EPSS: 4% chance of exploitation in the next 30 days.

A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.

Affected products

  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • Fedoraproject Fedora: version 32 only; version 33 only
  • Lxml Lxml: from 1.2, before 4.6.2 (fixed in 4.6.2)
  • Netapp Snapcenter: affected versions not specified
  • Oracle Communications Offline Mediation Controller: version 12.0.0.3.0 only
  • Oracle ZFS Storage Appliance Kit: version 8.8 only
  • Red Hat Enterprise Linux: version 8.0 only
  • Red Hat Software Collections: affected versions not specified

Published 2020-12-03. Last modified 2026-06-17.