StackRadar

CVE-2026-49825

High

Advisory

Published 8 Jul 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.002
15th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
13
of 17,787 indexed, latest versions
Container images
13
deployed by those charts
Fix available
2 of 3
affected packages

`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes

Carried by container images the latest versions of 13 of 17,787 indexed charts deploy, on 13 images.

Affected packageAffected versionsFixed inImages
lxml-html-cleanpypi0.1.1, 0.4.0, 0.4.1, 0.4.2+2 more0.4.59
lxmldeb4.8.0-1build1, 5.2.1-1, 5.4.0-1no fix listed3
python-lxmlrpm4.6.5-3.el90:4.6.5-3.el9_8.11
OSV records
DEBIAN-CVE-2026-49825GHSA-4jhm-jv67-739fRLSA-2026:66204UBUNTU-CVE-2026-49825
Also known as
PYSEC-2026-2614

Charts affected

13 by stars
ChartLatestAffected imagesRadar Score
openvpn-asas-helm-chartOfficialVerified publisher0.2.11 of 1See more

openvpn-as as-helm-chart 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-49825.

Container imageDigestPackageFixed in
openvpn/openvpn-as:latest2253c10ec652
lxml@5.2.1-1
no fix listed

Open the chart page →

2,716
mealieth-chartsVerified publisher0.5.11 of 1See more

mealie th-charts 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-49825.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
lxml-html-clean@0.4.3
0.4.5

Open the chart page →

3,816
mealiertomik-helm-chartsVerified publisher0.0.21 of 1See more

mealie rtomik-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-49825.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
lxml-html-clean@0.1.1
0.4.5

Open the chart page →

3,942
kitchenowlchart-kitchenowl0.1.121 of 2See more

kitchenowl chart-kitchenowl 0.1.12

1 of the 2 container images this version deploys carry CVE-2026-49825.

Container imageDigestPackageFixed in
tombursch/kitchenowl-backend:v0.7.8b48e4ab727cd
lxml-html-clean@0.4.4
0.4.5

Open the chart page →

4,783
csghubcsghubVerified publisher2.4.31 of 34See more

csghub csghub 2.4.3

1 of the 34 container images this version deploys carry CVE-2026-49825.

Container imageDigestPackageFixed in
opencsghq/label-studio:v2.4.0b4e849fcf94a
lxml-html-clean@0.4.0
0.4.5

Open the chart page →

59,131
dataflowcsghubVerified publisher2.5.01 of 7See more

dataflow csghub 2.5.0

1 of the 7 container images this version deploys carry CVE-2026-49825.

Container imageDigestPackageFixed in
opencsghq/label-studio:v2.5.047e22aa71870
lxml-html-clean@0.4.0
0.4.5

Open the chart page →

6,532
tandoorgabe565Verified publisher0.9.91 of 2See more

tandoor gabe565 0.9.9

1 of the 2 container images this version deploys carry CVE-2026-49825.

Container imageDigestPackageFixed in
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
lxml-html-clean@0.4.1
0.4.5

Open the chart page →

2,182
label-studioinseefrlab2.3.11 of 3See more

label-studio inseefrlab 2.3.1

1 of the 3 container images this version deploys carry CVE-2026-49825.

Container imageDigestPackageFixed in
heartexlabs/label-studio:latestaa461572e8f9
lxml-html-clean@0.4.0
0.4.5

Open the chart page →

3,157
inventreeinventreeOfficialVerified publisher0.4.281 of 2See more

inventree inventree 0.4.28

1 of the 2 container images this version deploys carry CVE-2026-49825.

Container imageDigestPackageFixed in
inventree/inventree:1.5.4a946ec09da3e
lxml@5.4.0-1
no fix listed

Open the chart page →

5,757
aperagkubeblocksVerified publisher0.0.0-nightly1 of 3See more

aperag kubeblocks 0.0.0-nightly

1 of the 3 container images this version deploys carry CVE-2026-49825.

Container imageDigestPackageFixed in
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
lxml-html-clean@0.4.2
0.4.5

Open the chart page →

8,455
powerdnspuckpuck2.0.01 of 4See more

powerdns puckpuck 2.0.0

1 of the 4 container images this version deploys carry CVE-2026-49825.

Container imageDigestPackageFixed in
pschiffe/pdns-admin:0.4.137ebba8c2b8f
python-lxml@4.6.5-3.el9
0:4.6.5-3.el9_8.1

Open the chart page →

4,614
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-49825.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
lxml-html-clean@0.4.3
0.4.5

Open the chart page →

4,537
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-49825.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
lxml@4.8.0-1build1
no fix listed

Open the chart page →

13,563

Container images carrying it

13 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
lxml-html-clean@0.4.2
0.4.5
1
heartexlabs/label-studio:latestaa461572e8f9
lxml-html-clean@0.4.0
0.4.5
1
inventree/inventree:1.5.4a946ec09da3e
lxml@5.4.0-1
no fix listed
1
opencsghq/label-studio:v2.5.047e22aa71870
lxml-html-clean@0.4.0
0.4.5
1
opencsghq/label-studio:v2.4.0b4e849fcf94a
lxml-html-clean@0.4.0
0.4.5
1
openvpn/openvpn-as:latest2253c10ec652
lxml@5.2.1-1
no fix listed
1
pschiffe/pdns-admin:0.4.137ebba8c2b8f
python-lxml@4.6.5-3.el9
0:4.6.5-3.el9_8.1
1
tombursch/kitchenowl-backend:v0.7.8b48e4ab727cd
lxml-html-clean@0.4.4
0.4.5
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
lxml@4.8.0-1build1
no fix listed
1
vabene1111/recipes:2.3.50f8d061895e9
lxml-html-clean@0.4.3
0.4.5
1
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
lxml-html-clean@0.1.1
0.4.5
1
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
lxml-html-clean@0.4.3
0.4.5
1
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
lxml-html-clean@0.4.1
0.4.5
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.