High severity8.2NVD Advisory· Published Aug 20, 2026· Updated Sep 18, 2026
CVE-2026-49825
CVE-2026-49825
Description
lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in `lxml.html.defs.link_attrs were missing xlink:href`, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
lxml_html_cleanPyPI | < 0.4.5 | 0.4.5 |
Affected products
6- Range: <0.4.5
- osv-coords4 versionspkg:rpm/almalinux/python3-lxmlpkg:rpm/almalinux/python3.12-lxmlpkg:rpm/opensuse/python-lxml&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python-lxml_html_clean&distro=openSUSE%20Tumbleweed
< 4.6.5-3.el9_8.1+ 3 more
- (no CPE)range: < 4.6.5-3.el9_8.1
- (no CPE)range: < 4.9.3-2.el9_8.1
- (no CPE)range: < 6.1.1-1.1
- (no CPE)range: < 0.4.5-1.1
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-4jhm-jv67-739fghsaADVISORY
- github.com/fedora-python/lxml_html_clean/security/advisories/GHSA-4jhm-jv67-739fnvdWEB
- github.com/fedora-python/lxml_html_clean/commit/322357ac61c6cf80fcbaba53b4e92e31f3ded9f2nvd
- github.com/fedora-python/lxml_html_clean/releases/tag/0.4.5nvd
- github.com/lxml/lxml/commit/5927a6d5e851845140975d99b65461e255caaab0nvd
- github.com/lxml/lxml/releases/tag/lxml-6.1.1nvd
News mentions
0No linked articles in our index yet.