CVE-2026-49825

high Red Hat
CVSS v3 Base Score
8.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
EPSS Score
0.2%
Exploitation probability in 30 days
Top 85% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Confidentiality
High
Integrity
Low
Availability
None
Published: August 20, 2026 (17 days ago)
Last Modified: August 20, 2026
Vendor: Red Hat
Source: REDHAT

Description

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.

CWE

CWE-166

Affected Products

Lightspeed CoreMigration Toolkit for Applications 8Red Hat AI Inference ServerRed Hat Ansible Automation Platform 2Red Hat Ansible Automation Platform Ansible Core 2Red Hat Ceph Storage 7Red Hat Ceph Storage 8Red Hat Ceph Storage 9Red Hat Certification Program for Red Hat Enterprise Linux 9Red Hat Enterprise Linux 10

References