Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-96857.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-96857
Upstream
Published
2026-08-20T15:17:30Z
Modified
2026-09-21T05:34:22Z
Summary
CVE-2026-49825 affecting package python-lxml for versions less than 4.9.3-3
Details

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in lxml.html.defs.link_attrs were missing xlink:href, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.

References

Affected packages

Azure Linux:3 / python-lxml

Package

Name
python-lxml
Purl
pkg:rpm/azure-linux/python-lxml

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.9.3-3

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-96857.json"