CVE-2026-49825: Fedora-Python Lxml Html Clean
High severity, CVSS 8.2. EPSS: 0.3% chance of exploitation in the next 30 days.
lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.
Affected products
- Fedora-Python Lxml Html Clean: before 0.4.5 (fixed in 0.4.5)
- Lxml Lxml: before 6.1.1 (fixed in 6.1.1)
Published 2026-08-20. Last modified 2026-09-18.