THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-6827 (MEDIUM 6.1) — justhtml before 1.17.0 contains multiple security issues in sanitization, serialization, and programmatic DOM handling. When custom policies preserve foreign namespaces (SVG/MathML), dangerous content such as HTML integration points (SVG <foreignObject>, MathML <annotation-xml en

[NVD] CVE-2026-6827 (MEDIUM 6.1) — justhtml before 1.17.0 contains multiple security issues in sanitization, serialization, and programmatic DOM handling. When custom policies preserve foreign namespaces (SVG/MathML), dangerous content such as HTML integration points (SVG <foreignObject>, MathML <annotation-xml en

mednvdPublished 2026-08-23

CVE-2026-6827 CVSS: 6.1 MEDIUM Published: 2026-08-23T14:16:53.963

justhtml before 1.17.0 contains multiple security issues in sanitization, serialization, and programmatic DOM handling. When custom policies preserve foreign namespaces (SVG/MathML), dangerous content such as HTML integration points (SVG <foreignObject>, MathML <annotation-xml encoding="text/html">) and mutation-XSS parser-differen

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-6827