CVE-2026-49825High· 8.2▾ Twilightlxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. cont…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 21.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in lxml.html.defs.link_attrs were missing xlink:href, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
lxml_html_clean < 0.4.5Patched in:
lxml_html_clean 0.4.5Source: https://github.com/advisories/GHSA-4jhm-jv67-739f
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-71491High· 7.5sqlparse is a non-validating SQL parser module for Python
CVE-2026-67325High· 8.8GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature
CVE-2026-54770Medium· 6.1WebOb provides objects for HTTP requests and responses
CVE-2026-93432Medium· 6.1A flaw was found in the Quarkus Qute template engine
CVE-2024-23176Medium· 5.4An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2
CVE-2026-44283Medium· 4.3etcd: etcd: Authenticated user can bypass RBAC for unauthorized data access (CVE-2026-44283)