Junglewise Threat Intelligence

CVE-2026-68749: rrrene html_sanitize_ex ReDoS in CSS scrubber

CVE-2026-68749 · Severity: high · CVSS 7.5 · Published 2026-08-06

Technologies: Rrrene Htmlsanitizeex, Rrrene Html Sanitize Ex. Vendors: Rrrene.

Executive brief

html_sanitize_ex is a library used to clean potentially malicious HTML and CSS before display in web applications. An attacker can send carefully crafted CSS with very long declaration names to trigger exponential processing time in the CSS validation logic, causing the application server to consume all available CPU and become unresponsive to legitimate requests.

Technical details

This is a Regular Expression Denial of Service (ReDoS) vulnerability in the CSS property regex matcher within HtmlSanitizeEx.Scrubber.CSS.scrub/1. The vulnerable regex uses an unbounded greedy quantifier ([-\w]+) followed by a mandatory colon, causing catastrophic backtracking when matching a long run of word characters not followed by a colon. The regex engine tries matching at every offset, resulting in quadratic time complexity relative to CSS length. An unauthenticated attacker can send an 80 KB CSS declaration that consumes ~2.4 seconds of CPU per request; multiple concurrent requests saturate the BEAM scheduler and render the application unresponsive. No data exfiltration or code execution occurs; impact is CPU exhaustion only.

Affected products

  • rrrene html_sanitize_ex 0.3.1 to <1.4.5 and 1.5.0-rc.0 to <1.5.3

Timeline

  • 2026-08-06: disclosed
  • 2026-08-06: advisory: CVE-2026-68749 published

References

Related threats