
CVE-2026-68749 & 68750 (CVSS 8.2 High): the Elixir HTML sanitizer you trust to clean untrusted HTML pinned a BEAM scheduler for 2.4 s with ONE request. The fix was bounding a regex: [-\w]+ -> [-\w]{1,64}. Six characters. #Elixir #ReDoS #InfoSec https://www.hunt-benito.com/blog/the-sanitizer-is-the-weapon-cve-2026-68749-cve-2026-68750-quadratic-denial-of-service-in-elixirs-html_sanitize_ex/ https://t.co/eP0F0Kmjav
Post summary
The post discloses a high‑severity regex‑based DoS in Elixir's HTML sanitizer, provides the specific patch to limit match length, and summarizes the impact without indicating widespread exploitation.
