justhtml before 1.16.0 contains multiple HTML...
Critical severity
Unreviewed
Published
Aug 23, 2026
to the GitHub Advisory Database
•
Updated Aug 23, 2026
Description
Published by the National Vulnerability Database
Aug 23, 2026
Published to the GitHub Advisory Database
Aug 23, 2026
Last updated
Aug 23, 2026
justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potentially leading to cross-site scripting. The issues primarily affect advanced usage rather than the default JustHTML(..., sanitize=True) path for ordinary parsed HTML: mutating or reusing sanitization policy objects (including exported defaults) could weaken later sanitization; programmatic DOM input to sanitize()/sanitize_dom() could miss mixed-case tag names (e.g., ScRiPt, StYlE); crafted programmatic doctype names could serialize into active markup; and custom policies preserving SVG or MathML could allow animation elements, presentation attributes with external url(...) references, or DOM trees mislabeled as namespace="html" to bypass foreign-content checks. Fixed in 1.16.0.
References