๐Ÿ” CVE Alert

CVE-2026-49825

HIGH 8.2

lxml: javascript: URL bypass in Cleaner via xlink:href

CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.

CWE CWE-79 CWE-184
Vendor lxml
Product lxml
Published Aug 20, 2026
Stay Ahead of the Next One

Get instant alerts for lxml lxml

Be the first to know when new high vulnerabilities affecting lxml lxml are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
None

Affected Versions

lxml / lxml
< 6.1.1
fedora-python / lxml_html_clean
< 0.4.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/fedora-python/lxml_html_clean/security/advisories/GHSA-4jhm-jv67-739f github.com: https://github.com/fedora-python/lxml_html_clean/commit/322357ac61c6cf80fcbaba53b4e92e31f3ded9f2 github.com: https://github.com/lxml/lxml/commit/5927a6d5e851845140975d99b65461e255caaab0 github.com: https://github.com/fedora-python/lxml_html_clean/releases/tag/0.4.5 github.com: https://github.com/lxml/lxml/releases/tag/lxml-6.1.1