Is lxml healthy, maintained, and safe?
Maintained, but watch it — lxml has real signals (drift, thin maintenance, or advisories) worth tracking.
The verdict
On the OSPulse health scale, lxml lands at 55/100 — medium risk, computed deterministically from live PyPI release history, and the OSV vulnerability database. Maintained, but watch it — lxml has real signals (drift, thin maintenance, or advisories) worth tracking.
Its most recent release shipped on 17 June 2026 — 40 days ago — so development is clearly active. Across 127 releases the cadence has been steady, which is a good sign of an ongoing maintenance rhythm. PyPI doesn't expose a reliable maintainer count, so bus-factor isn't scored here — treat maintenance depth as unknown rather than assumed.
OSV lists 14 known advisories for lxml, including 1 high. Review whether your version is in the affected range and whether a fixed release is available before depending on it. Each advisory is listed with its OSV/GHSA identifier below.
lxml is usable but carries real signals — pin versions, watch for new advisories, and keep a fallback in mind. This is a one-time snapshot of a single package — real projects depend on dozens or hundreds of packages, and any one of them can drift or be compromised between releases. Run your own requirements.txt through the free health check, or have OSPulse monitor your whole dependency tree continuously.
Evidence trail — deterministic, auditable
Known vulnerabilities (14)
lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through
lxml Cross-site Scripting Via Control Characters
lxml vulnerable to Cross-Site Scripting
lxml vulnerable to Cross-site Scripting
lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files
lxml NULL Pointer Dereference allows attackers to cause a denial of service
Improper Neutralization of Input During Web Page Generation in LXML
Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via control characters in the link scheme to
An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, allowing a remote attacker to conduct XSS attacks, as
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A re
An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner class does not remove the formaction attrib
lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content
NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is used together with libxml2 2.9.10 through 2.9.14. libxml2 2.9.9 and earlie
lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in the default configuration (with resolve_entities=True) allows untrusted XML inp
Key facts
- Latest version
- v6.1.1
- Last release
- 17 June 2026 (40 days ago)
- Total releases
- 127
- First release
- 3 July 2007
- Package age
- 19.1 years
- Maintainers
- not exposed by PyPI
- Known advisories
- 14
- Confidence
- High
Frequently asked
Is lxml still maintained?
Yes — lxml released as recently as 17 June 2026 (40 days ago), so it is actively maintained.
Does lxml have known security vulnerabilities?
Yes — OSV lists 14 advisories for lxml. See the advisory list on this page for the OSV/GHSA identifiers.
Is lxml safe to use?
Maintained, but watch it — lxml has real signals (drift, thin maintenance, or advisories) worth tracking. OSPulse rates it 55/100 (medium risk) based on release recency, cadence and known vulnerabilities.
Other PyPI packages we've checked
lxml is one package. What about the other hundreds in your tree?
Paste your own requirements.txt into the free health check for an instant snapshot — or let OSPulse monitor your whole dependency tree continuously, before your CVE scanner wakes up.
Data from the PyPI registry & OSV.dev · snapshot generated 2026-07-27 · scores are deterministic and recomputed on each refresh.
