# CVE-2026-49825

## Summary

- **CVE ID:** CVE-2026-49825
- **Severity:** HIGH
- **CVSS Score:** 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N)
- **CWE:** CWE-79, CWE-184
- **Published:** Aug 20, 2026
- **Last Modified:** Aug 21, 2026

## Description

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.

## Affected Products

- lxml — lxml (< 6.1.1)
- fedora-python — lxml_html_clean (< 0.4.5)

## References

- [CNA](https://github.com/fedora-python/lxml_html_clean/security/advisories/GHSA-4jhm-jv67-739f)
- [CNA](https://github.com/fedora-python/lxml_html_clean/commit/322357ac61c6cf80fcbaba53b4e92e31f3ded9f2)
- [CNA](https://github.com/lxml/lxml/commit/5927a6d5e851845140975d99b65461e255caaab0)
- [CNA](https://github.com/fedora-python/lxml_html_clean/releases/tag/0.4.5)
- [CNA](https://github.com/lxml/lxml/releases/tag/lxml-6.1.1)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.24%
- **EPSS Percentile:** 15.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._