Current section
6 Advisories
Jump to
Current section
6 Advisories
Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-68750.html
- https://github.com/rrrene/html_sanitize_ex/commit/507a6fb95dd4c466cac8a8355d8989043e9fbcc1
- https://github.com/rrrene/html_sanitize_ex/commit/9f5ccedbed230930813f992a1e6906fcf485981e
- https://github.com/rrrene/html_sanitize_ex/security/advisories/GHSA-463q-p2fr-mh9p
- https://hex.pm/packages/html_sanitize_ex
Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-68749.html
- https://github.com/rrrene/html_sanitize_ex/commit/4f4bd9eb254881462c0461fbab74b29188c2c133
- https://github.com/rrrene/html_sanitize_ex/commit/b673df33ddf982c8bd0a8bd6348aa247080b3b14
- https://github.com/rrrene/html_sanitize_ex/security/advisories/GHSA-4cx2-987x-rr2x
- https://hex.pm/packages/html_sanitize_ex
CSS sanitizer allowlist bypass in html_sanitize_ex via non-declaration input
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-68747.html
- https://github.com/rrrene/html_sanitize_ex/commit/0b9f9ad63a7529d4f2c3c1134c371adc3e654308
- https://github.com/rrrene/html_sanitize_ex/commit/c311a499db0b0baef06493fb3cfeb730c0f18f28
- https://github.com/rrrene/html_sanitize_ex/security/advisories/GHSA-87v2-pfhj-r5x7
- https://hex.pm/packages/html_sanitize_ex
html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowing forced cross-origin redirection
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-66829.html
- https://github.com/rrrene/html_sanitize_ex/commit/29454dc99513fd9b5b6429ab7b6695ad09889227
- https://github.com/rrrene/html_sanitize_ex/commit/9f7e38be51edc38f132dfe994f37af5cf5e0e76f
- https://github.com/rrrene/html_sanitize_ex/security/advisories/GHSA-2c6f-3j54-xpcr
- https://hex.pm/packages/html_sanitize_ex
html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attributes, allowing form hijacking
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-66370.html
- https://github.com/rrrene/html_sanitize_ex/commit/21394e758cb0ffe12fb9953c30fdedc6016c8f9e
- https://github.com/rrrene/html_sanitize_ex/commit/a1e804ed997e780ea71d14393cf2f701330553a6
- https://github.com/rrrene/html_sanitize_ex/security/advisories/GHSA-w3f9-jjhw-wwvq
- https://hex.pm/packages/html_sanitize_ex
html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, allowing untrusted content embedding
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-66843.html
- https://github.com/rrrene/html_sanitize_ex/commit/bec27fec4de99e40c68c4285a610e09e791a3eaf
- https://github.com/rrrene/html_sanitize_ex/commit/ce038aa1af5a960d50f8eb5d368cc57bb2b9a9f0
- https://github.com/rrrene/html_sanitize_ex/security/advisories/GHSA-xmm9-jc22-rcgj
- https://hex.pm/packages/html_sanitize_ex