Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-49825

HIGH NVD
CVSS Score 8.2
Severity HIGH
Published Aug 20, 2026
Vendor unknown

Description

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.

References