logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2020-26303

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2020-26303

Description:
insane is a whitelist-oriented HTML sanitizer. Versions 2.6.2 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available.
Last updated date:
11/13/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
11/13/2024
Reference url to background

https://securitylab.github.com/advisories/GHSL-2020-289-redos-insane/

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy