PT-2021-17026 · Unknown · Sanitize-Html

Boutell

·

Published

2021-02-08

·

Updated

2026-06-04

·

CVE-2021-26539

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions sanitize-html versions prior to 2.3.1
Description The issue arises from improper handling of internationalized domain names (IDN), which could allow an attacker to bypass hostname whitelist validation set by the allowedIframeHostnames option. This could potentially lead to malicious activities.
Recommendations For versions prior to 2.3.1, update to version 2.3.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the allowedIframeHostnames option until a patch is applied.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-26539
GHSA-RJQQ-98F6-6J3R

Affected Products

Sanitize-Html