{"apiVersion":"1.0","identifier":"CVE-2026-7808","description":"justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potentially leading to cross-site scripting. The issues primarily affect advanced usage rather than the default JustHTML(..., sanitize=True) path for ordinary parsed HTML: mutating or reusing sanitization policy objects (including exported defaults) could weaken later sanitization; programmatic DOM input to sanitize()/sanitize_dom() could miss mixed-case tag names (e.g., ScRiPt, StYlE); crafted programmatic doctype names could serialize into active markup; and custom policies preserving SVG or MathML could allow animation elements, presentation attributes with external url(...) references, or DOM trees mislabeled as namespace=-html- to bypass foreign-content checks. Fixed in 1.16.0.","publishedAt":"2026-08-23T14:16:54","lastModifiedAt":"2026-08-26T17:10:53","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-7808","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","epssProbability":0.00352,"riskScore":1.01,"affectedProduct":"justhtml","affectedVersions":"<1.16.0","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-7808","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-7808","en":"https://www.redsauce.net/en/cves/CVE-2026-7808","fr":"https://www.redsauce.net/fr/cves/CVE-2026-7808","pt":"https://www.redsauce.net/pt/cves/CVE-2026-7808","de":"https://www.redsauce.net/de/cves/CVE-2026-7808","sk":"https://www.redsauce.net/sk/cves/CVE-2026-7808","el":"https://www.redsauce.net/el/cves/CVE-2026-7808"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-7808"}}