Junglewise Threat Intelligence

CVE-2026-7808: justhtml HTML sanitization bypass leading to XSS

CVE-2026-7808 · Severity: critical · CVSS 9.8 · Published 2026-08-23

Technologies: Emil Stenstrom Justhtml.

Executive brief

justhtml is a Python library that sanitizes HTML to prevent malicious content like scripts and styles from being executed. A flaw in versions before 1.16.0 allows dangerous content to survive sanitization under certain conditions, potentially enabling attackers to inject and execute malicious scripts. This could allow attackers to steal user data, session cookies, or perform actions on behalf of users.

Technical details

justhtml before 1.16.0 contains multiple HTML sanitization bypass vulnerabilities (CWE-20, CWE-79, CWE-178, CWE-436, CWE-471) that allow active/dangerous content to survive sanitization and lead to cross-site scripting (XSS). The vulnerabilities include: (1) mutation or reuse of sanitization policy objects weakening later sanitization; (2) programmatic DOM input missing mixed-case tag names (e.g., ScRiPt, StYlE); (3) crafted doctype names serializing into active markup; and (4) custom policies preserving SVG or MathML allowing animation elements, external url() references, or mislabeled DOM trees to bypass foreign-content checks. These issues primarily affect advanced usage paths rather than the default JustHTML(..., sanitize=True) configuration for ordinary parsed HTML. The vulnerability is fixed in version 1.16.0.

Affected products

  • Emil Stenstrom justhtml before 1.16.0

Timeline

  • 2026-04-12: disclosed: Security advisory GHSA-4p64-v8f5-r2gx published
  • 2026-04-12: patched: Version 1.16.0 released with fixes
  • 2026-08-23: advisory: CVE-2026-7808 assigned and published on NVD

References