Search CVE reports


Toggle filters

1 – 2 of 2 results


CVE-2024-21501

Medium priority
Needs evaluation

Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including...

1 affected package

node-sanitize-html

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-sanitize-html Needs evaluation Needs evaluation Not in release Not in release
Show less packages

CVE-2022-25887

Medium priority

Some fixes available 4 of 14

The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment removal.

2 affected packages

jupyter-notebook, node-sanitize-html

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jupyter-notebook Fixed Fixed Not affected Not affected
node-sanitize-html Needs evaluation Needs evaluation Not in release Not in release
Show less packages