CVE-2026-68750
- EPSS 0.44%
- Veröffentlicht 06.08.2026 14:50:20
- Zuletzt bearbeitet 19.08.2026 12:18:35
Inefficient Algorithmic Complexity vulnerability in the traversal engine in rrrene html_sanitize_ex allows an unauthenticated remote attacker to exhaust server CPU and memory via a flat run of sibling elements in sanitized HTML. The list clause of Ht...
CVE-2026-68749
- EPSS 0.44%
- Veröffentlicht 06.08.2026 14:50:12
- Zuletzt bearbeitet 19.08.2026 12:18:35
Inefficient Regular Expression Complexity vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to exhaust server CPU via a long CSS declaration in sanitized HTML. The declaration regex in HtmlSanitize...
CVE-2026-68747
- EPSS 0.25%
- Veröffentlicht 06.08.2026 14:50:03
- Zuletzt bearbeitet 19.08.2026 12:18:35
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to inject CSS at-rules, including an import of a...
CVE-2026-66829
- EPSS 0.5%
- Veröffentlicht 06.08.2026 14:49:23
- Zuletzt bearbeitet 19.08.2026 12:18:34
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to force visitors of a page to navigate to a site of the attacker's choosing via a <meta http-equiv="refresh">...
CVE-2026-66370
- EPSS 0.23%
- Veröffentlicht 06.08.2026 14:49:15
- Zuletzt bearbeitet 19.08.2026 12:18:34
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to retarget a form already on the rendering page and receive whatever the victim submits, inc...
CVE-2026-66843
- EPSS 0.29%
- Veröffentlicht 06.08.2026 14:48:20
- Zuletzt bearbeitet 19.08.2026 12:18:34
Inclusion of Functionality from Untrusted Control Sphere vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to load a document of their choosing into a trusted page via the data attribute of an <object> element in...