CVE-2026-66843 - html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, allowing untrusted content embedding
CVE ID :CVE-2026-66843
Published : Aug. 6, 2026, 4:16 p.m. | 3 hours, 10 minutes ago
Description :Inclusion of Functionality from Untrusted Control Sphere vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to load a document of their choosing into a trusted page via the data attribute of an
Published : Aug. 6, 2026, 4:16 p.m. | 3 hours, 10 minutes ago
Description :Inclusion of Functionality from Untrusted Control Sphere vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to load a document of their choosing into a trusted page via the data attribute of an