AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-66843

MEDIUM · CVSS 6.1 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The vulnerability in the HTML5 scrubber of the affected Java library allows remote attackers to load arbitrary documents into trusted pages through the data attribute of an <object> element, bypassing security controls due to insufficient URI validation. While this does not lead to unconditional cross-site scripting, it could facilitate the loading of untrusted content if the application serves attacker-controlled content from a same-origin path. Organizations using html_sanitize_ex versions from 0.3.1 to before 1.5.3 should prioritize patching to mitigate potential risks associated with this vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-66843
Severity
MEDIUM
CVSS
6.1
EPSS
0.29%
Java

Original NVD Description

Inclusion of Functionality from Untrusted Control Sphere vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to load a document of their choosing into a trusted page via the data attribute of an <object> element in sanitized HTML. object is the one URI-bearing element in lib/html_sanitize_ex/scrubber/html5.ex never registered through allow_tag_with_uri_attributes/3, and its only guard is a prefix match on lowercase "javascript:", so mixed-case variants, data: URIs, protocol-relative URLs and same-origin paths all survive. This is not unconditional cross-site scripting. A javascript: URL does not execute through <object data> in current browsers, data: documents load in an opaque origin, and host-origin script execution additionally requires the application to serve attacker-controlled content from a same-origin path. This issue affects html_sanitize_ex: from 0.3.1 before 1.5.3.

Related CVEs

Other vulnerabilities affecting the same vendor(s)