CVE-2026-49825
lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.
वीकनेस
lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.
संदर्भ
- https://github.com/fedora-python/lxml_html_clean/commit/322357ac61c6cf80fcbaba53b4e92e31f3ded9f2
- https://github.com/fedora-python/lxml_html_clean/releases/tag/0.4.5
- https://github.com/fedora-python/lxml_html_clean/security/advisories/GHSA-4jhm-jv67-739f
- https://github.com/lxml/lxml/commit/5927a6d5e851845140975d99b65461e255caaab0
- https://github.com/lxml/lxml/releases/tag/lxml-6.1.1
- https://github.com/fedora-python/lxml_html_clean/security/advisories/GHSA-4jhm-jv67-739f
हमलावर से पहले बग आप ढूँढें।
GitHub से साइन इन करें और एक मिनट से भी कम में अपना पहला ऑडिट चलाएँ। फ़्री प्लान के लिए क्रेडिट कार्ड की ज़रूरत नहीं।