CVE-2026-49825 - lxml: URL bypass in Cleaner via xlink:href
Brief
CVE ID : CVE-2026-49825
Published : Aug. 20, 2026, 2:42 p. m.
- 27 minutes ago
Description : lxml is a library for processing XML and HTML in the Python language. Prior to 6.
- 1, link attributes in ``lxml. html. defs. link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.
- 1 and lxml_html_clean 0.
- 5.
Severity: 0.0
- NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
