html_sanitize_ex
Hex6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting html_sanitize_expage 1 of 1
- CVE-2026-66370MEDIUMCVSS 6.1EG 6.1fixed in 1.4.5 or 1.5.3, by version range2026-08-06
vulnerable: 0.3.1 ... 1.5.2 (21 versions)
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to retarget a form already on the rendering page and receive whatever the victim s…
- CVE-2026-66829MEDIUMCVSS 6.1EG 6.1fixed in 1.4.5 or 1.5.3, by version range2026-08-06
vulnerable: 0.3.1 ... 1.5.2 (21 versions)
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to force visitors of a page to navigate to a site of the attacker's choosing via a <meta http-equiv…
- CVE-2026-66843MEDIUMCVSS 6.1EG 6.1fixed in 1.4.5 or 1.5.3, by version range2026-08-06
vulnerable: 0.3.1 ... 1.5.2 (21 versions)
Inclusion of Functionality from Untrusted Control Sphere vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to load a document of their choosing into a trusted page via the data attribute of an <object>…
- CVE-2026-68747MEDIUMCVSS 6.1EG 6.1fixed in 1.4.5 or 1.5.4, by version range2026-08-06
vulnerable: 0.3.1 ... 1.5.3 (22 versions)
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to inject CSS at-rules, including an …
- CVE-2026-68749HIGHCVSS 7.5EG 7.5fixed in 1.4.5 or 1.5.3, by version range2026-08-06
vulnerable: 0.3.1 ... 1.5.2 (21 versions)
Inefficient Regular Expression Complexity vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to exhaust server CPU via a long CSS declaration in sanitized HTML. The declaration regex in H…
- CVE-2026-68750HIGHCVSS 7.5EG 7.5fixed in 1.4.5 or 1.5.3, by version range2026-08-06
vulnerable: 0.3.1 ... 1.5.2 (21 versions)
Inefficient Algorithmic Complexity vulnerability in the traversal engine in rrrene html_sanitize_ex allows an unauthenticated remote attacker to exhaust server CPU and memory via a flat run of sibling elements in sanitized HTML. The list c…
Check whether html_sanitize_ex is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for html_sanitize_ex CVEs against the assets you own.
Book a Demo →