1.13.0
3 months ago
6 days ago
Known vulnerabilities in the justhtml package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
justhtml is an A pure Python HTML5 parser that just works. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the How to fix Cross-site Scripting (XSS)? Upgrade | [,1.13.0) |
justhtml is an A pure Python HTML5 parser that just works. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the serialization process of raw-text elements such as Note: This is only exploitable if a custom policy is used that allows How to fix Cross-site Scripting (XSS)? Upgrade | [,1.12.0) |
justhtml is an A pure Python HTML5 parser that just works. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the How to fix Cross-site Scripting (XSS)? Upgrade | [,1.12.0) |
justhtml is an A pure Python HTML5 parser that just works. Affected versions of this package are vulnerable to Uncontrolled Recursion in the construction, when parsing deeply nested HTML structures. An attacker can cause the application to terminate unexpectedly or fail requests by supplying HTML input with excessive nesting, which triggers unbounded recursion and results in an unhandled How to fix Uncontrolled Recursion? Upgrade | [,1.10.0) |