← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 20, 2026 · 14:42via CVEFeed

CVE-2026-49825 - lxml: URL bypass in Cleaner via xlink:href

Brief

CVE ID : CVE-2026-49825

Published : Aug. 20, 2026, 2:42 p. m.

  • 27 minutes ago

Description : lxml is a library for processing XML and HTML in the Python language. Prior to 6.

  • 1, link attributes in ``lxml. html. defs. link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.
  • 1 and lxml_html_clean 0.
  • 5.

Severity: 0.0

  • NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed