Critical justhtml Sanitization Bypass Vulnerabilities Discovered

Critical justhtml Sanitization Bypass Vulnerabilities Discovered

First seen 23 Aug 2026, 19:46 UTC FeedlySecurityarsenalnvd.nist.govTheexploitdesk.TechSecurityfocus+3 72.6

Article Content

Browse articles
ThreatCluster

Multiple critical vulnerabilities have been identified in the justhtml library, specifically CVE-2026-5388, CVE-2026-7808, and CVE-2026-8445, all published on 2026-08-23. These vulnerabilities allow attackers to bypass HTML sanitization, potentially leading to cross-site scripting (XSS) attacks. The flaws affect justhtml versions prior to 1.15.0 for CVE-2026-5388 and 1.16.0 for CVE-2026-7808, with a CVSS score of 9.8 assigned to each. Attack vectors include encoded URLs, programmatic DOM manipulation, and improper handling of Markdown inputs. Applications using justhtml for rendering user-supplied content are at risk, necessitating immediate upgrades to mitigate potential exploitation. No public proof-of-concept exploits have been reported yet, but the vulnerabilities are considered severe due to their potential impact on user sessions and application integrity.

Key Points: • CVE-2026-5388 and CVE-2026-7808 both scored 9.8 on the CVSS scale, indicating critical severity. • Vulnerabilities allow attackers to bypass HTML sanitization, leading to potential XSS attacks. • Immediate upgrades to justhtml version 1.15.0 or later are necessary to mitigate risks.

Timeline

2026-08-23
CVE-2026-5388 published
Critical sanitization bypass vulnerabilities in justhtml library disclosed, affecting versions prior to 1.15.0.
Securityarsenal
2026-08-23
CVE-2026-7808 published
Another critical vulnerability in justhtml allowing HTML sanitization bypass was disclosed, affecting versions before 1.16.0.
Feedly
2026-08-23
CVE-2026-8445 published
A critical sanitizer bypass vulnerability in justhtml was published, allowing raw HTML injection during Markdown conversion.
Feedly