VDB

CVE-2026-49825

CVE-2026-49825 PUBLISHED CVSS 8.2 HIGH

Reported by GitHub_M · Published August 20, 2026

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.

Risk Scores

CVSS 3.1
8.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

Affected Products

VendorProductVersions
lxmllxml< 6.1.1
fedora-pythonlxml_html_clean< 0.4.5
PyPIlxml-html-clean0
lxmllxml< 6.1.1, < 6.1.1
fedora-pythonlxml_html_clean< 0.4.5, < 0.4.5

Timeline

  • Jun 29, 2026 CVE Published
  • Aug 7, 2026 Security Advisory
  • Aug 24, 2026 EPSS Score
  • Sep 2, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›