Security Advisories for html_sanitize_ex in hex
High
21 days ago
Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service
hex
html_sanitize_ex
High
21 days ago
Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service
hex
html_sanitize_ex
Low
21 days ago
CSS sanitizer allowlist bypass in html_sanitize_ex via non-declaration input
hex
html_sanitize_ex
Low
21 days ago
html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowing forced cross-origin redirection
hex
html_sanitize_ex
Medium
21 days ago
html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attributes, allowing form hijacking
hex
html_sanitize_ex
Low
21 days ago
html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, allowing untrusted content embedding
hex
html_sanitize_ex