Home

Description

lol-html can cause panics on certain HTML inputs. Anyone processing arbitrary 3rd party HTML with the library is affected.

PUBLISHED Reserved 2023-08-08 | Published 2023-08-16 | Updated 2024-10-02 | Assigner cloudflare




HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

CWE-20 Improper Input Validation

Product status

Default status
unaffected

Any version before 1.1.1
affected

References

github.com/...l-html/security/advisories/GHSA-c3x7-354f-4p2x

github.com/...l-html/security/advisories/GHSA-c3x7-354f-4p2x

cve.org (CVE-2023-4241)

nvd.nist.gov (CVE-2023-4241)

Download JSON