Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
8.2
CVE-2026-61824
- EPSS 0.23%
- Veröffentlicht 21.08.2026 21:17:01
- Zuletzt bearbeitet 21.08.2026 21:17:01
Defuddle cleans up HTML pages. Prior to 0.19.1, site extractors interpolate page-derived image alt and src values, og:image values, and video descriptions into HTML strings without context-appropriate escaping, and buildExtractorResponse() returns th...
6.1
CVE-2026-30830
- EPSS 0.25%
- Veröffentlicht 07.03.2026 05:49:15
- Zuletzt bearbeitet 11.03.2026 18:50:35
Defuddle cleans up HTML pages. Prior to version 0.9.0, the _findContentBySchemaText method in src/defuddle.ts interpolates image src and alt attributes directly into an HTML string without escaping. An attacker can use a " in the alt attribute to bre...
1