CVE-2026-68750: CWE-407 Inefficient Algorithmic Complexity in rrrene html_sanitize_ex
CVE-2026-68750 is an inefficient algorithmic complexity vulnerability in the html_sanitize_ex library by rrrene. The vulnerability arises in the traversal engine where processing a large number of sibling elements in sanitized HTML causes quadratic CPU and memory consumption. This can be triggered remotely without authentication by submitting allowed HTML tags with many sibling elements. The issue affects versions from 0.3.1 up to but not including 1.5.3.
AI Analysis
Technical Summary
The vulnerability in html_sanitize_ex's traversal engine is due to the list clause of HtmlSanitizeEx.Traverser.traverse/2 recursively processing the tail of sibling nodes and repeatedly flattening the list, resulting in quadratic time complexity relative to the number of sibling elements. Because the traverser is invoked on every public entry point and does not require special scrubber configurations, an unauthenticated remote attacker can exhaust server CPU and memory resources by submitting sanitized HTML containing a large flat run of sibling elements. For example, a 160 KB payload with 20,000 sibling elements can occupy a scheduler for approximately 1.7 seconds, with resource consumption growing faster than the payload size.
Potential Impact
An unauthenticated remote attacker can cause denial of service by exhausting server CPU and memory resources through specially crafted HTML payloads containing many sibling elements. This can degrade or disrupt service availability due to the quadratic traversal cost in the vulnerable versions of html_sanitize_ex.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch is currently documented. Until a patch is available, consider limiting the size or complexity of HTML inputs processed by html_sanitize_ex to reduce the risk of resource exhaustion.
CVE-2026-68750: CWE-407 Inefficient Algorithmic Complexity in rrrene html_sanitize_ex
Description
CVE-2026-68750 is an inefficient algorithmic complexity vulnerability in the html_sanitize_ex library by rrrene. The vulnerability arises in the traversal engine where processing a large number of sibling elements in sanitized HTML causes quadratic CPU and memory consumption. This can be triggered remotely without authentication by submitting allowed HTML tags with many sibling elements. The issue affects versions from 0.3.1 up to but not including 1.5.3.
CVSS v4.0
Score 8.2high
Affected software
cpe:2.3:a:rrrene:html_sanitize_ex:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in html_sanitize_ex's traversal engine is due to the list clause of HtmlSanitizeEx.Traverser.traverse/2 recursively processing the tail of sibling nodes and repeatedly flattening the list, resulting in quadratic time complexity relative to the number of sibling elements. Because the traverser is invoked on every public entry point and does not require special scrubber configurations, an unauthenticated remote attacker can exhaust server CPU and memory resources by submitting sanitized HTML containing a large flat run of sibling elements. For example, a 160 KB payload with 20,000 sibling elements can occupy a scheduler for approximately 1.7 seconds, with resource consumption growing faster than the payload size.
Potential Impact
An unauthenticated remote attacker can cause denial of service by exhausting server CPU and memory resources through specially crafted HTML payloads containing many sibling elements. This can degrade or disrupt service availability due to the quadratic traversal cost in the vulnerable versions of html_sanitize_ex.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch is currently documented. Until a patch is available, consider limiting the size or complexity of HTML inputs processed by html_sanitize_ex to reduce the risk of resource exhaustion.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- EEF
- Date Reserved
- 2026-07-31T13:23:00.355Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a74ab42bf8831d539ec74f7
Added to database: 08/06/2026, 15:41:54 UTC
Last enriched: 08/06/2026, 15:56:10 UTC
Last updated: 08/06/2026, 16:01:11 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.