Current section
1 Advisory
Jump to
Current section
1 Advisory
lazy_html serializes SVG and MathML style and script text unescaped, allowing mutation XSS
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-92106.html
- https://github.com/dashbitco/lazy_html/commit/1dee15746c024916b3110af8b168c2f3b3065fbd
- https://github.com/dashbitco/lazy_html/commit/f32c7fd6223225b68bc8691c78b6d4a77972f1d5
- https://github.com/dashbitco/lazy_html/security/advisories/GHSA-8rqp-v692-v82q
- https://hex.pm/packages/lazy_html
Checksum
Dependency Config
mix.exs
rebar.config
Gleam
erlang.mk
Package Details
this version
43 215
yesterday
30 820
last 7 days
158 793
all time
3 290 411