Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-49825

Опубликовано: 20 авг. 2026
Источник: nvd
CVSS3: 8.2
EPSS Низкий

Описание

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in lxml.html.defs.link_attrs were missing xlink:href, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.

EPSS

Процентиль: 15%
0.0024
Низкий

8.2 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 8.2
ubuntu
18 дней назад

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.

CVSS3: 8.2
redhat
18 дней назад

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.

msrc
17 дней назад

lxml: javascript: URL bypass in Cleaner via xlink:href

CVSS3: 8.2
debian
18 дней назад

lxml is a library for processing XML and HTML in the Python language. ...

CVSS3: 8.2
github
2 месяца назад

`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes

EPSS

Процентиль: 15%
0.0024
Низкий

8.2 High

CVSS3

Дефекты

CWE-79