Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-49825

Опубликовано: 20 авг. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 8.2

Описание

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in lxml.html.defs.link_attrs were missing xlink:href, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.

РелизСтатусПримечание
devel

needs-triage

esm-infra-legacy/trusty

needs-triage

esm-infra-legacy/xenial

needs-triage

esm-infra/bionic

needs-triage

esm-infra/focal

needs-triage

jammy

needs-triage

noble

needs-triage

resolute

needs-triage

upstream

needs-triage

Показывать по

Ссылки на источники

EPSS

Процентиль: 15%
0.0024
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
redhat
18 дней назад

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.

CVSS3: 8.2
nvd
18 дней назад

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.

msrc
17 дней назад

lxml: javascript: URL bypass in Cleaner via xlink:href

CVSS3: 8.2
debian
18 дней назад

lxml is a library for processing XML and HTML in the Python language. ...

CVSS3: 8.2
github
2 месяца назад

`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes

EPSS

Процентиль: 15%
0.0024
Низкий

8.2 High

CVSS3