rpm package
almalinux/python3.12-lxml
pkg:rpm/almalinux/python3.12-lxml
Vulnerabilities (1)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-49825 | Hig | 8.2 | < 4.9.3-2.el9_8.1 | 4.9.3-2.el9_8.1 | Aug 20, 2026 | lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6 |
- affected < 4.9.3-2.el9_8.1fixed 4.9.3-2.el9_8.1
lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6