html_sanitize_ex
Hex6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting html_sanitize_expage 1 of 1
- CVE-2026-66370MEDIUMCVSS 6.1EG 6.1✓ Fixed in 1.5.32026-08-06
vulnerable: 0.3.1 ... 1.5.2 (21 versions)
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to retarget a form already on the rendering page and receive whatever the victim s…
- CVE-2026-66829MEDIUMCVSS 6.1EG 6.1✓ Fixed in 1.5.32026-08-06
vulnerable: 0.3.1 ... 1.5.2 (21 versions)
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to force visitors of a page to navigate to a site of the attacker's choosing via a <meta http-equiv…
- CVE-2026-66843MEDIUMCVSS 6.1EG 6.1✓ Fixed in 1.5.32026-08-06
vulnerable: 0.3.1 ... 1.5.2 (21 versions)
Inclusion of Functionality from Untrusted Control Sphere vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to load a document of their choosing into a trusted page via the data attribute of an <object>…
- CVE-2026-68747MEDIUMCVSS 6.1EG 6.1✓ Fixed in 1.5.42026-08-06
vulnerable: 0.3.1 ... 1.5.3 (22 versions)
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to inject CSS at-rules, including an …
- CVE-2026-68749HIGHCVSS 7.5EG 7.5✓ Fixed in 1.5.32026-08-06
vulnerable: 0.3.1 ... 1.5.2 (21 versions)
Inefficient Regular Expression Complexity vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to exhaust server CPU via a long CSS declaration in sanitized HTML. The declaration regex in H…
- CVE-2026-68750HIGHCVSS 7.5EG 7.5✓ Fixed in 1.5.32026-08-06
vulnerable: 0.3.1 ... 1.5.2 (21 versions)
Inefficient Algorithmic Complexity vulnerability in the traversal engine in rrrene html_sanitize_ex allows an unauthenticated remote attacker to exhaust server CPU and memory via a flat run of sibling elements in sanitized HTML. The list c…
Check whether html_sanitize_ex is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for html_sanitize_ex CVEs against the assets you own.
Start Free Scan →