CVE-2026-7808Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potentially leading to cross-site scripting. The issues primarily affect advanced usage rather than the default JustHTML(..., sanitize=True) path for ordinary parsed HTML: mutating or reusing sanitization policy objects (including exported defaults) could weaken later sanitization; programmatic DOM input to sanitize()/sanitize_dom() could miss mixed-case tag names (e.g., ScRiPt, StYlE); crafted programmatic doctype names could serialize into active markup; and custom policies preserving SVG or MathML could allow animation elements, presentation attributes with external url(...) references, or DOM trees mislabeled as namespace="html" to bypass foreign-content checks. Fixed in 1.16.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • 5 total mentions across 1 day

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-08-23: 5Patch / Workaround · 2026-08-23: 1Technical Details · 2026-08-23: 508-23
Signal classification1 categories
Disclosure
5100.0%
Referenced assets5 URLs
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-7808 justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potent… https://www.cve.org/CVERecord?id=CVE-2026-7808

    Post summary

    The post reports that justhtml versions before 1.16.0 contain HTML sanitization bypass flaws permitting scripts or styles to survive, but provides no PoC, exploit code, patch information, or evidence of active exploitation.

    020201.8K
    58.1K followersView on X
  • NewNormal Security@NewScanTeam
    Disclosure

    NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 23 Aug 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan today: 📦 HTML sanitization bypass — unsafe markup can remain active in rendered application content, as seen in justhtml CVE-2026-7808 and CVE-2026-5388 📦 Markdown cross-site scripting — crafted content can render as active HTML, as seen in justhtml CVE-2026-8445 📦 Resource exhaustion — crafted selectors or links can exhaust server-side parsing resources, as seen in justhtml CVE-2026-4671 Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #XSS #CSO #REDTEAM

    Post summary

    The post announces several justhtml CVEs, describing them as HTML sanitization bypass, XSS, or resource exhaustion, but offers no evidence of PoC, exploitation, or patches.

    0001051
    5 followersView on X
  • ADK Cyber@ADKCyber
    Disclosure

    CVE-2026-7808 (CVSS 9.8): justhtml before 1.16.0 has HTML sanitization bypasses that can permit XSS. Update the library if present in your stack. https://nvd.nist.gov/vuln/detail/CVE-2026-7808 via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/a6oNRpeojG

    Post summary

    The tweet announces CVE‑2026‑7808, noting an XSS vulnerability in justhtml, recommends updating the library, and provides an NVD link.

    0000043
    93 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7808 justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potent… https://www.cve.org/CVERecord?id=CVE-2026-7808 ----- Traducción: CVE-2026-7808 jus… http://infoflow.cloud`

    Post summary

    The notice announces CVE-2026-7808, highlighting that justhtml versions prior to 1.16.0 are vulnerable to HTML sanitization bypass allowing potentially malicious script or style content to persist.

    0000025
    102 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7808 HTML Sanitization Bypass in justhtml Before 1.16.0 Leads to Cross-Site Scripting https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7808

    Post summary

    The post references CVE-2026-7808, describing an HTML sanitization bypass in justhtml before version 1.16.0 that can lead to XSS, but does not provide any PoC, exploit code, active exploitation evidence, or patch details.

    00000119
    4.1K followersView on X

Explore more