Security Advisories for html_sanitize_ex in hex
High
about 5 hours ago
Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service
hex
html_sanitize_ex
High
about 5 hours ago
Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service
hex
html_sanitize_ex
Low
about 5 hours ago
CSS sanitizer allowlist bypass in html_sanitize_ex via non-declaration input
hex
html_sanitize_ex
Low
about 5 hours ago
html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowing forced cross-origin redirection
hex
html_sanitize_ex
Medium
about 5 hours ago
html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attributes, allowing form hijacking
hex
html_sanitize_ex
Low
about 5 hours ago
html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, allowing untrusted content embedding
hex
html_sanitize_ex