Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2026-49825

18 дней назад

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.

CVSS3: 8.2
EPSS: Низкий
redhat логотип

CVE-2026-49825

18 дней назад

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2026-49825

18 дней назад

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.

CVSS3: 8.2
EPSS: Низкий
msrc логотип

CVE-2026-49825

17 дней назад

lxml: javascript: URL bypass in Cleaner via xlink:href

EPSS: Низкий
debian логотип

CVE-2026-49825

18 дней назад

lxml is a library for processing XML and HTML in the Python language. ...

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-4jhm-jv67-739f

2 месяца назад

`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes

CVSS3: 8.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-49825

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.

CVSS3: 8.2
0%
Низкий
18 дней назад
redhat логотип
CVE-2026-49825

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.

CVSS3: 8.2
0%
Низкий
18 дней назад
nvd логотип
CVE-2026-49825

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.

CVSS3: 8.2
0%
Низкий
18 дней назад
msrc логотип
CVE-2026-49825

lxml: javascript: URL bypass in Cleaner via xlink:href

0%
Низкий
17 дней назад
debian логотип
CVE-2026-49825

lxml is a library for processing XML and HTML in the Python language. ...

CVSS3: 8.2
0%
Низкий
18 дней назад
github логотип
GHSA-4jhm-jv67-739f

`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes

CVSS3: 8.2
0%
Низкий
2 месяца назад

Уязвимостей на страницу