CVE-2021-28957 21.03.21 06:15 lxml 4.6.2 places the HTML action attribute into defs.link_attrs (in html/defs.py) for later use in input sanitization, but does not do the same for the HTML5 formaction attribute. Upstream fixed it in 4.6.3 ( https://github.com/lxml/lxml/commit/2d01a1ba8984e0483ce6619b972832377f208a0d ), so we should probably upgrade to that. Has lots of dependents so I suppose it needs grafting? Is that useful and does it work for Python packages? Léo