ammonia
crates.io3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting ammoniapage 1 of 1
- CVE-2019-15542HIGHCVSS 7.5EG 7.5fixed in 2.1.02019-08-26
An issue was discovered in the ammonia crate before 2.1.0 for Rust. There is uncontrolled recursion during HTML DOM tree serialization.
- CVE-2021-38193MEDIUMCVSS 6.1EG 6.1fixed in 3.1.0 or 2.1.3, by version range2021-08-08
An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870.
- CVE-2026-102342MEDIUMCVSS 5.4EG 5.4fixed in 3.3.3, 4.0.3 or 4.1.4, by version range2026-09-29
Ammonia: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') The following SVG will produce a link with a `javascript` scheme. If the user clicks this link, they will run it. ```svg <svg xmlns="http://www…
Check whether ammonia is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for ammonia CVEs against the assets you own.
Book a Demo →