CVE-2026-49825
HighAdvisory
Published 8 Jul 2026In the index since 6 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.2
- base score, highest
- EPSS
- 0.002
- 15th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 13
- of 17,787 indexed, latest versions
- Container images
- 13
- deployed by those charts
- Fix available
- 2 of 3
- affected packages
`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes
Carried by container images the latest versions of 13 of 17,787 indexed charts deploy, on 13 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| lxml-html-cleanpypi | 0.1.1, 0.4.0, 0.4.1, 0.4.2+2 more | 0.4.5 | 9 |
| lxmldeb | 4.8.0-1build1, 5.2.1-1, 5.4.0-1 | no fix listed | 3 |
| python-lxmlrpm | 4.6.5-3.el9 | 0:4.6.5-3.el9_8.1 | 1 |
- OSV records
- DEBIAN-CVE-2026-49825GHSA-4jhm-jv67-739fRLSA-2026:66204UBUNTU-CVE-2026-49825
- Also known as
- PYSEC-2026-2614
Charts affected
13 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| openvpn-asas-helm-chartOfficialVerified publisher | 0.2.1 | 1 of 1See more | 2,716 |
| mealieth-chartsVerified publisher | 0.5.1 | 1 of 1See more | 3,816 |
| mealiertomik-helm-chartsVerified publisher | 0.0.2 | 1 of 1See more | 3,942 |
| kitchenowlchart-kitchenowl | 0.1.12 | 1 of 2See more | 4,783 |
| csghubcsghubVerified publisher | 2.4.3 | 1 of 34See more | 59,131 |
| dataflowcsghubVerified publisher | 2.5.0 | 1 of 7See more | 6,532 |
| tandoorgabe565Verified publisher | 0.9.9 | 1 of 2See more | 2,182 |
| label-studioinseefrlab | 2.3.1 | 1 of 3See more | 3,157 |
| inventreeinventreeOfficialVerified publisher | 0.4.28 | 1 of 2See more | 5,757 |
| aperagkubeblocksVerified publisher | 0.0.0-nightly | 1 of 3See more | 8,455 |
| powerdnspuckpuck | 2.0.0 | 1 of 4See more | 4,614 |
| tandoorrtomik-helm-chartsVerified publisher | 0.0.1 | 1 of 1See more | 4,537 |
| twenty-crmvictorlane | 0.0.1 | 1 of 3See more | 13,563 |
Container images carrying it
13 by charts deploying them
A fixed version is listed for 2 of the 3 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| apecloud/ | 8ac9947a2c84 | lxml-html-clean | 0.4.5 | 1 |
| heartexlabs/ | aa461572e8f9 | lxml-html-clean | 0.4.5 | 1 |
| inventree/ | a946ec09da3e | lxml | no fix listed | 1 |
| opencsghq/ | 47e22aa71870 | lxml-html-clean | 0.4.5 | 1 |
| opencsghq/ | b4e849fcf94a | lxml-html-clean | 0.4.5 | 1 |
| openvpn/ | 2253c10ec652 | lxml | no fix listed | 1 |
| pschiffe/ | 37ebba8c2b8f | python-lxml | 0:4.6.5-3.el9_8.1 | 1 |
| tombursch/ | b48e4ab727cd | lxml-html-clean | 0.4.5 | 1 |
| twentycrm/ | 2f78405a78be | lxml | no fix listed | 1 |
| vabene1111/ | 0f8d061895e9 | lxml-html-clean | 0.4.5 | 1 |
| ghcr.io/ | 322369a5b748 | lxml-html-clean | 0.4.5 | 1 |
| ghcr.io/ | bb2939094eed | lxml-html-clean | 0.4.5 | 1 |
| ghcr.io/ | 063eb446e298 | lxml-html-clean | 0.4.5 | 1 |