CVE-2026-49825
EUVD-2026-6339020.08.2026, 15:17
lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| lxml | lxml | 𝑥 < 6.1.1 | CNA |
| lxml | lxml | 𝑥 < 0.4.5 | CNA |
References