CVE-2026-4671General

LOWCVSS 8.7 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkification. Applications that evaluate attacker-controlled selector strings (via query(), matches(), or selector-based transforms), run selector matching over very large untrusted documents, construct DOM trees from untrusted structure, or enable linkification over attacker-controlled text may consume disproportionate CPU or memory. Triggers include oversized selectors, large selector lists, oversized compound selectors, long combinator chains, deeply nested functional pseudo-classes, repeated token/positional matching, cyclic DOM graphs causing non-terminating traversal, and punctuation-heavy or trailing-bracket linkification input. These are availability-only concerns and do not by themselves allow script execution, data disclosure, or sanitizer bypass. Default JustHTML(sanitize=True) usage is not expected to be exposed, since selectors are normally supplied by application code.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-23: 3Technical Details · 2026-08-23: 308-23
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • NewNormal Security@NewScanTeam
    General

    NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 23 Aug 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan today: 📦 HTML sanitization bypass — unsafe markup can remain active in rendered application content, as seen in justhtml CVE-2026-7808 and CVE-2026-5388 📦 Markdown cross-site scripting — crafted content can render as active HTML, as seen in justhtml CVE-2026-8445 📦 Resource exhaustion — crafted selectors or links can exhaust server-side parsing resources, as seen in justhtml CVE-2026-4671 Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #XSS #CSO #REDTEAM

    Post summary

    The post delivers a daily tally of newly reported CVEs with brief technical descriptions, but does not provide PoC, exploits, patches, or evidence of active exploitation.

    0001051
    5 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-4671 justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkification. Applications that evaluate attacker-controlle… https://www.cve.org/CVERecord?id=CVE-2026-4671 ----- Traducción: CVE-2026-4671 jus… http://infoflow.cloud`

    Post summary

    CVE-2026-4671 is a newly disclosed low‑severity denial‑of‑service vulnerability in justhtml before 1.18.0, affecting CSS selector handling and linkification.

    0000025
    102 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-4671 justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkification. Applications that evaluate attacker-controlle… https://www.cve.org/CVERecord?id=CVE-2026-4671

    Post summary

    The note briefly reports a low‑severity denial‑of‑service vulnerability in justhtml, listing affected behaviors, but offers no PoC, exploit code, patch details, or evidence of active exploitation.

    00000929
    58.0K followersView on X

Explore more