CVE-2026-68750Patch(rrrene / htmlsanitizeex)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch rrrene htmlsanitizeex systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Inefficient Algorithmic Complexity vulnerability in the traversal engine in rrrene html_sanitize_ex allows an unauthenticated remote attacker to exhaust server CPU and memory via a flat run of sibling elements in sanitized HTML. The list clause of HtmlSanitizeEx.Traverser.traverse/2 recurses on the tail of a sibling list and then evaluates List.flatten([head] ++ tail) over the already flattened result, so every one of n siblings copies and re-walks the entire remaining tail. The flattening is only needed for the rare case where scrub returns several replacement nodes for one node, but the cost is paid across the whole tail at every step, making traversal quadratic in sibling count. The traverser sits on every public entry point, so no particular scrubber or configuration is required and the payload needs only allowed tags. A 160 KB body of 20,000 sibling elements occupies a scheduler for roughly 1.7 seconds, and the cost grows faster than the body does. This issue affects html_sanitize_ex: from 0.3.1 before 1.4.5 and from 1.5.0-rc.0 before 1.5.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-407

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • htmlsanitizeex

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
htmlsanitizeex

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-13: 1Patch / Workaround · 2026-08-13: 1Technical Details · 2026-08-13: 108-13
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • Hunt-Benito@HB_CyberSec
    Patch

    CVE-2026-68749 & 68750 (CVSS 8.2 High): the Elixir HTML sanitizer you trust to clean untrusted HTML pinned a BEAM scheduler for 2.4 s with ONE request. The fix was bounding a regex: [-\w]+ -> [-\w]{1,64}. Six characters. #Elixir #ReDoS #InfoSec https://www.hunt-benito.com/blog/the-sanitizer-is-the-weapon-cve-2026-68749-cve-2026-68750-quadratic-denial-of-service-in-elixirs-html_sanitize_ex/ https://t.co/eP0F0Kmjav

    Post summary

    The post discloses a high‑severity regex‑based DoS in Elixir's HTML sanitizer, provides the specific patch to limit match length, and summarizes the impact without indicating widespread exploitation.

    0000048
    3 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apprrrenehtmlsanitizeex---

Explore more