{"id":"CVE-2026-49825","title":"lxml is a library for processing XML and HTML in the Python language","summary":"lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. cont…","severity":"high","cvss":8.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N","cwe":["CWE-79","CWE-184","CWE-166"],"vendor":"Red Hat","product":"Red Hat OpenStack Platform 16.2","affected":["lightspeed_core","migration_toolkit_for_applications 8","ai_inference_server","ansible_automation_platform 2","ansible_automation_platform_ansible_core 2","ceph_storage 7","ceph_storage 8","ceph_storage 9","certification_program_for_red_hat_enterprise_linux 9","enterprise_linux 10","enterprise_linux 6","enterprise_linux 7","enterprise_linux 8","enterprise_linux 9","openshift_ai_rhoai","openshift_container_platform 4","openstack_platform 16.2","openstack_platform 18.0","quay 3","satellite 6","update_infrastructure_4_for_cloud_providers","update_infrastructure 5","enterprise_linux_appstream_v_8","enterprise_linux_appstream_e4s_v_9_2","enterprise_linux_appstream_e4s_v_9_4","enterprise_linux_appstream_eus_v_9_6","enterprise_linux_appstream_v_9"],"patched":["enterprise_linux_appstream_v_8","enterprise_linux_appstream_e4s_v_9_2","enterprise_linux_appstream_e4s_v_9_4","enterprise_linux_appstream_eus_v_9_6","enterprise_linux_appstream_v_9"],"published":"2026-08-20","updated":"2026-09-18","sourceUpdated":"2026-09-18T20:05:53.723","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-49825","references":[{"url":"https://github.com/fedora-python/lxml_html_clean/commit/322357ac61c6cf80fcbaba53b4e92e31f3ded9f2","label":"security-advisories@github.com"},{"url":"https://github.com/fedora-python/lxml_html_clean/releases/tag/0.4.5","label":"security-advisories@github.com"},{"url":"https://github.com/fedora-python/lxml_html_clean/security/advisories/GHSA-4jhm-jv67-739f","label":"security-advisories@github.com"},{"url":"https://github.com/lxml/lxml/commit/5927a6d5e851845140975d99b65461e255caaab0","label":"security-advisories@github.com"},{"url":"https://github.com/lxml/lxml/releases/tag/lxml-6.1.1","label":"security-advisories@github.com"},{"url":"https://github.com/fedora-python/lxml_html_clean/security/advisories/GHSA-4jhm-jv67-739f","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49825.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-49825"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2520368"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-49825"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49825"},{"url":"https://access.redhat.com/errata/RHSA-2026:67943"},{"url":"https://access.redhat.com/errata/RHSA-2026:67326"},{"url":"https://access.redhat.com/errata/RHSA-2026:67325"},{"url":"https://access.redhat.com/errata/RHSA-2026:67324"},{"url":"https://access.redhat.com/errata/RHSA-2026:66204"},{"url":"https://access.redhat.com/errata/RHSA-2026:66203"},{"url":"https://github.com/advisories/GHSA-4jhm-jv67-739f"},{"url":"https://access.redhat.com/errata/RHSA-2026:67279"},{"url":"https://access.redhat.com/errata/RHSA-2026:67956"}],"tags":["nvd","csaf","vex","red-hat","ghsa","pip"],"epss":0.0024,"epssPercentile":0.15333,"aliases":["GHSA-4jhm-jv67-739f"],"ecosystem":"pip","ingestedAt":"2026-07-08T20:46:41.641Z","slug":"CVE-2026-49825","body":"## Overview\n\nlxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-49825)\n\nAffected packages:\n\n- `lxml_html_clean < 0.4.5`\n\nPatched in:\n\n- `lxml_html_clean 0.4.5`\n\nSource: https://github.com/advisories/GHSA-4jhm-jv67-739f\n\n## Vendor advisories\n\n- **RHSA-2026:67943** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:67943)\n- **RHSA-2026:67326** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.2) · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67326)\n- **RHSA-2026:67325** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4) · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67325)\n- **RHSA-2026:67324** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6) · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67324)\n- **RHSA-2026:66204** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-09-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:66204)\n- **RHSA-2026:66203** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-09-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:66203)\n- **Red Hat VEX** · Important · affected: Lightspeed Core, Migration Toolkit for Applications 8, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform Ansible Core 2, Red Hat Ceph Storage 7, … · no fix planned: Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat Update Infrastructure 4 for Cloud Providers, Red Hat Update Infrastructure 5, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49825.json)\n- **RHSA-2026:67279** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.7 · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67279)\n- **RHSA-2026:67956** · Red Hat · fixed in: Red Hat Update Infrastructure 5 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:67956)","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":45.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}