Current section

6 Advisories

Jump to
EEF-CVE-2026-68750 CVE-2026-68750 GHSA-463q-p2fr-mh9p

Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service

August 06, 2026
EEF-CVE-2026-68749 CVE-2026-68749 GHSA-4cx2-987x-rr2x

Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service

August 06, 2026
EEF-CVE-2026-68747 CVE-2026-68747 GHSA-87v2-pfhj-r5x7

CSS sanitizer allowlist bypass in html_sanitize_ex via non-declaration input

August 06, 2026
EEF-CVE-2026-66829 CVE-2026-66829 GHSA-2c6f-3j54-xpcr

html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowing forced cross-origin redirection

August 06, 2026
EEF-CVE-2026-66370 CVE-2026-66370 GHSA-w3f9-jjhw-wwvq

html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attributes, allowing form hijacking

August 06, 2026
EEF-CVE-2026-66843 CVE-2026-66843 GHSA-xmm9-jc22-rcgj

html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, allowing untrusted content embedding

August 06, 2026

Checksum

Dependency Config

mix.exs

rebar.config

Gleam

erlang.mk

Package Details

Downloads Last 30 days, all versions
0 2K 4K 6K 8K

this version

0

yesterday

6 997

last 7 days

39 240

all time

8 444 462

Last Updated

Aug 06, 2026

License

MIT

Build Tools

mix

Publisher

rrrene rrrene

Links

Owners