Threats Tagged 'ghsa-6g7x-33rf-28v3'
View all threats tagged with 'ghsa-6g7x-33rf-28v3'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa-6g7x-33rf-28v3'
Click on any threat for detailed analysis and mitigation recommendations
Inclusion of Functionality from Untrusted Control Sphere vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to… (CVE-2026-66843)CVE-2026-66843 0 CVE-2026-66843 is a vulnerability in the HTML5 scrubber of the html_sanitize_ex library that allows a remote attacker to load arbitrary documents into a trusted page via the data attribute of an <object> element in sanitized HTML. The vulnerability arises because the <object> element is not properly registered or guarded against certain URI schemes, allowing mixed-case javascript:, data: URIs, protocol-relative URLs, and same-origin paths to bypass filtering. However, this does not result in unconditional cross-site scripting due to browser restrictions on javascript: URLs in <object data> and the opaque origin of data: documents. Exploitation requires the application to serve attacker-controlled content from a same-origin path. This issue affects html_sanitize_ex versions from 0.3.1 up to but not including 1.5.3. Join the discussion | GCVE Database | 08/06/2026, 18:30:50 UTC Added: 08/11/2026, 18:54:10 UTC |
Showing 1 to 1 of 1 result