PT-2025-40281 · Crates.Io · Ammonia

Published

2025-09-21

·

Updated

2025-09-21

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML.
This vulnerability only has an effect when the svg or math tag is allowed, because it relies on a tag being parsed as html during the cleaning process, but serialized in a way that causes in to be parsed as xml by the browser.
Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These [elements] are:
  • title
  • textarea
  • xmp
  • iframe
  • noembed
  • noframes
  • plaintext
  • noscript
  • style
  • script
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

RUSTSEC-2025-0071

Affected Products

Ammonia