VDB
CVE-2026-49825
CVE-2026-49825
PUBLISHED
CVSS 8.2 HIGH
Reported by GitHub_M · Published August 20, 2026
lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.
Risk Scores
CVSS 3.1
8.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| lxml | lxml | < 6.1.1 |
| fedora-python | lxml_html_clean | < 0.4.5 |
| PyPI | lxml-html-clean | 0 |
| lxml | lxml | < 6.1.1, < 6.1.1 |
| fedora-python | lxml_html_clean | < 0.4.5, < 0.4.5 |
Timeline
- Jun 29, 2026 CVE Published
- Aug 7, 2026 Security Advisory
- Aug 24, 2026 EPSS Score
- Sep 2, 2026 EPSS Score
References
- https://github.com/fedora-python/lxml_html_clean/security/advisories/GHSA-4jhm-jv67-739f x_refsource_CONFIRM
- https://github.com/fedora-python/lxml_html_clean/commit/322357ac61c6cf80fcbaba53b4e92e31f3ded9f2 x_refsource_MISC
- https://github.com/lxml/lxml/commit/5927a6d5e851845140975d99b65461e255caaab0 x_refsource_MISC
- https://github.com/fedora-python/lxml_html_clean/releases/tag/0.4.5 x_refsource_MISC
- https://github.com/lxml/lxml/releases/tag/lxml-6.1.1 x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2026-49825 advisory
- https://github.com/advisories/GHSA-4jhm-jv67-739f advisory