lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.
CVSS Details
- CVSS 3.1 Base Score: 8.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade lxml | Sep 30, 2026 | Aug 20, 2026 |
| Redhat_linux | — | Upgrade python3.12-lxmlUpgrade python3-lxmlNo solution existsUpgrade python3.12-lxml-debugsourceUpgrade python3.12-lxml-debuginfoUpgrade python3-lxml-debuginfoUpgrade python-lxml-debugsource | Aug 31, 2026 | Aug 20, 2026 |
| Rocky_linux | — | Upgrade python3.12-lxmlUpgrade python3.12-lxml-debuginfoUpgrade python3.12-lxml-debugsourceUpgrade python-lxml-debugsourceUpgrade python3-lxml-debuginfoUpgrade python3-lxml | Sep 15, 2026 | Sep 11, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub