Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-49825

Опубликовано: 20 авг. 2026
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in lxml.html.defs.link_attrs were missing xlink:href, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.

A flaw was found in lxml, a library for processing XML and HTML in Python. The lxml.html.defs.link_attrs were missing xlink:href, which could allow an attacker to bypass URL filtering mechanisms. This vulnerability enables URL bypass attacks in embedded content such as Scalable Vector Graphics (SVG) or Mathematical Markup Language (MathML), potentially leading to information disclosure or arbitrary code execution in the context of the user's browser.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Lightspeed Corelightspeed-core/lightspeed-stack-rhel9Affected
Lightspeed Corelightspeed-core/rag-tool-cpu-rhel9Affected
Lightspeed Corelightspeed-core/rag-tool-cuda-12.9-rhel9Affected
Migration Toolkit for Applications 8mta/mta-solution-server-rhel9Affected
Red Hat AI Inference Serverrhaiis/vllm-neuron-rhel9Affected
Red Hat AI Inference Serverrhaii/vllm-neuron-rhel9Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/controller-rhel8Will not fix
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/eda-controller-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-minimal-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-minimal-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-166
https://bugzilla.redhat.com/show_bug.cgi?id=2520368lxml: lxml-html-clean: lxml: URL bypass vulnerability in Cleaner via missing xlink:href

EPSS

Процентиль: 15%
0.0024
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
ubuntu
18 дней назад

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.

CVSS3: 8.2
nvd
18 дней назад

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.

msrc
17 дней назад

lxml: javascript: URL bypass in Cleaner via xlink:href

CVSS3: 8.2
debian
18 дней назад

lxml is a library for processing XML and HTML in the Python language. ...

CVSS3: 8.2
github
2 месяца назад

`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes

EPSS

Процентиль: 15%
0.0024
Низкий

8.2 High

CVSS3