justhtml
PyPI9 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting justhtmlpage 1 of 1
- CVE-2026-4671HIGHCVSS 7.5EG 7.5✓ Fixed in 1.18.02026-08-23
vulnerable: 0.1.0 ... 1.9.1 (62 versions)
justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkification. Applications that evaluate attacker-controlled selector strings (via query(), matches(), or selector-based transform…
- CVE-2026-5388CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.15.02026-08-23
vulnerable: 0.1.0 ... 1.9.1 (59 versions)
justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passthrough=True), and several custom sanitization-policy edge ca…
- CVE-2026-5389MEDIUMCVSS 6.1EG 6.1✓ Fixed in 1.13.02026-08-23
vulnerable: 0.1.0 ... 1.9.1 (57 versions)
justhtml versions before 1.13.0 contain a cross-site scripting vulnerability in the to_markdown() function when serializing attacker-controlled pre content. Attackers can place backticks inside sanitized pre elements to break out of fixed-…
- CVE-2026-5751MEDIUMCVSS 6.1EG 6.1✓ Fixed in 1.14.02026-08-23
vulnerable: 1.13.0
justhtml versions 1.13.0 and earlier contain a parser-differential / mutation cross-site scripting (mXSS) vulnerability when using a custom SanitizationPolicy that preserves foreign namespaces (e.g., drop_foreign_namespaces=False with allo…
- CVE-2026-6827MEDIUMCVSS 6.1EG 6.1✓ Fixed in 1.17.02026-08-23
vulnerable: 0.1.0 ... 1.9.1 (61 versions)
justhtml before 1.17.0 contains multiple security issues in sanitization, serialization, and programmatic DOM handling. When custom policies preserve foreign namespaces (SVG/MathML), dangerous content such as HTML integration points (SVG <…
- CVE-2026-7808CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.16.02026-08-23
vulnerable: 0.1.0 ... 1.9.1 (60 versions)
justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potentially leading to cross-site scripting. The issues primarily affect adva…
- CVE-2026-8445CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.12.02026-08-23
vulnerable: 0.1.0 ... 1.9.1 (56 versions)
justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a parsed document to Markdown via to_markdown(). While a small set of Markdown metacharacte…
- CVE-2026-8630MEDIUMCVSS 6.1EG 6.1✓ Fixed in 1.12.02026-08-23
vulnerable: 0.1.0 ... 1.9.1 (56 versions)
justhtml before 1.12.0 (versions <= 1.11.0) contains a mutation cross-site scripting (mXSS) vulnerability in the serialization of raw-text elements such as <style> and <script>. When a DOM tree is processed by sanitize_dom() using a custom…
- CVE-2026-9769HIGHCVSS 7.5EG 7.5✓ Fixed in 1.10.02026-08-23
vulnerable: 0.1.0 ... 1.9.1 (54 versions)
justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() construction, TreeBuilder.finish() unconditionally calls _populate_selectedcontent(), which recursively traver…
Check whether justhtml is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for justhtml CVEs against the assets you own.
Start Free Scan →