PT-2026-79768 · Justhtml · Justhtml

·

CVE-2026-4671

·

Published

2026-05-08

·

Updated

2026-08-24

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions justhtml versions prior to 1.18.0
Description Multiple low-severity denial-of-service issues exist in CSS selector handling and linkification. Applications may consume disproportionate CPU or memory when evaluating attacker-controlled selector strings via query(), matches(), or selector-based transforms, running selector matching over very large untrusted documents, constructing DOM trees from untrusted structure, or enabling linkification over attacker-controlled text. Triggers include oversized selectors, large selector lists, oversized compound selectors, long combinator chains, deeply nested functional pseudo-classes, repeated token/positional matching, cyclic DOM graphs causing non-terminating traversal, and punctuation-heavy or trailing-bracket linkification input. These issues affect availability and do not allow script execution, data disclosure, or sanitizer bypass.
Recommendations Update to version 1.18.0 or later.

Exploit

Fix

DoS

Resource Exhaustion

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-4671
GHSA-R8CJ-3554-33MR

Affected Products

Justhtml