Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| rrrene | html_sanitize_ex | 0.3.1 ~ 1.5.4 | cpe:2.3:a:rrrene:html_sanitize_ex:*:*:*:*:*:*:*:* | |
| rrrene | html_sanitize_ex | 21f90012eb21aa36f4e3701b7547e12faf0f3c8b ~ 0b9f9ad63a7529d4f2c3c1134c371adc3e654308 | cpe:2.3:a:rrrene:html_sanitize_ex:*:*:*:*:*:*:*:* |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-68749 | 8.2 HIGH | Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion de |
| CVE-2026-68750 | 8.2 HIGH | Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaus |
| CVE-2026-66370 | 4.8 MEDIUM | html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attributes, allow |
| CVE-2026-66829 | 2.3 LOW | html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowing forced cros |
| CVE-2026-66843 | 2.3 LOW | html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, allowing untr |
No comments yet