Skip to content

Denial of service with deeply nested HTML tags.

Moderate
mat-sz published GHSA-hhw2-373g-hx77 Jul 8, 2026

Package

npm lettersanitizer (npm)

Affected versions

< 1.0.7

Patched versions

1.0.8

Description

Impact

Denial of service (DoS) vulnerability, does not allow remote code execution or anything of the sort.

Patches

Patched in 1.0.8.

Workarounds

No workarounds besides upgrading.

References

See this pull request: #10

Severity

Moderate

CVE ID

CVE-2026-75527

Weaknesses

No CWEs

Credits