Skip to content

lxml 6.0.0 is not supported #263

Description

@harshitsengar

https://pypi.org/project/lxml/#history

A new version was released by lxml and our requirements.txt needs version lxml>=4.6.5

However with the latest version connector is failing

Activity

  1. setrawicana commented on Oct 13, 2025

    @setrawicana

    Hi, following up with this, lxml@5.4.0 has been marked to have Stack-based Buffer Overflow by Checkmarx (CVE-2025-6170). According to it, the remediate to this vulnerability is on 6.0.2 fyi

  2. jamesdow21 commented on Oct 13, 2025

    @jamesdow21
    Contributor

    What was the problem that lxml >= 6.0 was causing?

    As far as I can tell, lxml is only used within redshift_connector as the specified parser for BeautifulSoup4 when parsing SAML responses within the Active Directory Federation Services Identity Provider plugin in redshift_connecter/plugin/adfs_credentials_provider.py

    The modified dependency with the upper bound makes it impossible to install redshift_connector on Python 3.14 (without building lxml from source).

    If the upper bound is left in place instead of fixing the underlying problem, then redshift_connector is effectively ending support at Python 3.13

  3. jamesdow21 commented on Oct 15, 2025

    @jamesdow21
    Contributor

    @timm4205 I see that you have made the past couple of releases for this library

    Can you weigh in on this issue and/or the related #267?

  4. bmos commented on Nov 14, 2025

    @bmos

    What was the problem that lxml >= 6.0 was causing?

    It looks like it may have been related to this behavior change noted earlier this year:

    When you build a BeautifulSoup from a plain text, that text was getting wrapped into a <p> tag when the installed lxml version is earlier than 6, but isn’t any more with the new version of lxml.
    -- Luc Saffre

    Or perhaps:

    Fixed an unhandled exception when parsing invalid markup that contains the { character
    when using lxml==6.0.0. [bug=2116306]
    -- bs4 changelog for 4.13.5 (20250824)

    It'd be a good idea to bump the version of beautifulsoup4 and remove the lxml upper bound to see if the problem has been fixed in bs4.

  5. timm4205 commented on Mar 31, 2026

    @timm4205
    Contributor

    The fix to increase upper bound for lxml to support python 3.14 and bump the bs4 version as well are implemented in 2.1.13 release

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions