CVE-2026-49825

🟡 Monitoruj

Brak atrybutu xlink:href w lxml umożliwia ataki omijające URL w osadzonym SVG/MathML.

CVSS
8.2
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS8.2
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2026-08-20 15:17:30 UTC
Ostatnia modyfikacja (NVD)2026-08-21 17:16:31 UTC
Referencje