OSPulse

Is lxml healthy, maintained, and safe?

55/ 100
lxmlv6.1.1
Medium riskconfidence: Highview on pypi.org

Maintained, but watch it — lxml has real signals (drift, thin maintenance, or advisories) worth tracking.

vital-signs traceirregular · weakening

The verdict

On the OSPulse health scale, lxml lands at 55/100 — medium risk, computed deterministically from live PyPI release history, and the OSV vulnerability database. Maintained, but watch it — lxml has real signals (drift, thin maintenance, or advisories) worth tracking.

Its most recent release shipped on 17 June 2026 — 40 days ago — so development is clearly active. Across 127 releases the cadence has been steady, which is a good sign of an ongoing maintenance rhythm. PyPI doesn't expose a reliable maintainer count, so bus-factor isn't scored here — treat maintenance depth as unknown rather than assumed.

OSV lists 14 known advisories for lxml, including 1 high. Review whether your version is in the affected range and whether a fixed release is available before depending on it. Each advisory is listed with its OSV/GHSA identifier below.

lxml is usable but carries real signals — pin versions, watch for new advisories, and keep a fallback in mind. This is a one-time snapshot of a single package — real projects depend on dozens or hundreds of packages, and any one of them can drift or be compromised between releases. Run your own requirements.txt through the free health check, or have OSPulse monitor your whole dependency tree continuously.

Evidence trail — deterministic, auditable

Last release recency
40 days ago · active
Release cadence
steady · typical gap ~39d
Maintainer bus factor
not available from PyPI — not penalised
Known vulnerabilities (OSV)
14 advisories · 1 high
-45
Package age
19.1 years · 127 releases

Known vulnerabilities (14)

  • GHSA-55x5-fj6c-h6m8MODERATECVE-2021-43818PYSEC-2021-852

    lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through

  • GHSA-57qw-cc2g-pv5pMODERATECVE-2014-3146PYSEC-2014-9

    lxml Cross-site Scripting Via Control Characters

  • GHSA-jq4v-f5q6-mjqqMODERATECVE-2021-28957PYSEC-2021-19

    lxml vulnerable to Cross-Site Scripting

  • GHSA-pgww-xf46-h92rMODERATECVE-2020-27783PYSEC-2020-62

    lxml vulnerable to Cross-site Scripting

  • GHSA-vfmq-68hx-4jfwHIGHCVE-2026-41066PYSEC-2026-87

    lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files

  • GHSA-wrxv-2j5q-m38wMODERATECVE-2022-2309PYSEC-2022-230

    lxml NULL Pointer Dereference allows attackers to cause a denial of service

  • GHSA-xp26-p53h-6h2pMODERATECVE-2018-19787PYSEC-2018-12

    Improper Neutralization of Input During Web Page Generation in LXML

  • PYSEC-2014-9UNKNOWNCVE-2014-3146GHSA-57qw-cc2g-pv5p

    Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via control characters in the link scheme to

  • PYSEC-2018-12UNKNOWNCVE-2018-19787GHSA-xp26-p53h-6h2p

    An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, allowing a remote attacker to conduct XSS attacks, as

  • PYSEC-2020-62UNKNOWNCVE-2020-27783GHSA-pgww-xf46-h92r

    A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A re

  • PYSEC-2021-19UNKNOWNCVE-2021-28957GHSA-jq4v-f5q6-mjqq

    An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner class does not remove the formaction attrib

  • PYSEC-2021-852UNKNOWNCVE-2021-43818GHSA-55x5-fj6c-h6m8

    lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content

  • PYSEC-2022-230UNKNOWNCVE-2022-2309GHSA-wrxv-2j5q-m38w

    NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is used together with libxml2 2.9.10 through 2.9.14. libxml2 2.9.9 and earlie

  • PYSEC-2026-87LOWCVE-2026-41066GHSA-vfmq-68hx-4jfw

    lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in the default configuration (with resolve_entities=True) allows untrusted XML inp

Key facts

Latest version
v6.1.1
Last release
17 June 2026 (40 days ago)
Total releases
127
First release
3 July 2007
Package age
19.1 years
Maintainers
not exposed by PyPI
Known advisories
14
Confidence
High

Frequently asked

Is lxml still maintained?

Yes — lxml released as recently as 17 June 2026 (40 days ago), so it is actively maintained.

Does lxml have known security vulnerabilities?

Yes — OSV lists 14 advisories for lxml. See the advisory list on this page for the OSV/GHSA identifiers.

Is lxml safe to use?

Maintained, but watch it — lxml has real signals (drift, thin maintenance, or advisories) worth tracking. OSPulse rates it 55/100 (medium risk) based on release recency, cadence and known vulnerabilities.

Other PyPI packages we've checked

Browse all checked packages →

lxml is one package. What about the other hundreds in your tree?

Paste your own requirements.txt into the free health check for an instant snapshot — or let OSPulse monitor your whole dependency tree continuously, before your CVE scanner wakes up.

Data from the PyPI registry & OSV.dev · snapshot generated 2026-07-27 · scores are deterministic and recomputed on each refresh.