Vulnerabilities & PatchesEmerging1 src
CVE-2026-49825 - lxml: URL bypass in Cleaner via xlink:href
CVE ID : CVE-2026-49825
Published : Aug. 20, 2026, 2:42 p. m.
• 27 minutes ago
Description : lxml is a library for processing XML and HTML in the Python language. Prior to 6. 1. 1, link attributes in ``lxml. html. defs. link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6. 1. 1 and lxml_html_clean 0. 4. 5.
Severity: 0.0
• NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...