Количество 6
Количество 6
CVE-2026-49825
lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.
CVE-2026-49825
lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.
CVE-2026-49825
lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.
CVE-2026-49825
lxml: javascript: URL bypass in Cleaner via xlink:href
CVE-2026-49825
lxml is a library for processing XML and HTML in the Python language. ...
GHSA-4jhm-jv67-739f
`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-49825 lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5. | CVSS3: 8.2 | 0% Низкий | 18 дней назад | |
CVE-2026-49825 lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5. | CVSS3: 8.2 | 0% Низкий | 18 дней назад | |
CVE-2026-49825 lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5. | CVSS3: 8.2 | 0% Низкий | 18 дней назад | |
CVE-2026-49825 lxml: javascript: URL bypass in Cleaner via xlink:href | 0% Низкий | 17 дней назад | ||
CVE-2026-49825 lxml is a library for processing XML and HTML in the Python language. ... | CVSS3: 8.2 | 0% Низкий | 18 дней назад | |
GHSA-4jhm-jv67-739f `lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes | CVSS3: 8.2 | 0% Низкий | 2 месяца назад |
Уязвимостей на страницу