CVE-2020-26303

insane is a whitelist-oriented HTML sanitizer. Versions 2.6.2 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available.
References
Link Resource
https://github.com/bevacqua/insane/issues/19 Issue Tracking Third Party Advisory
https://securitylab.github.com/advisories/GHSL-2020-289-redos-insane/ Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:bevacqua:insane:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-10-26 21:15

Updated : 2024-11-13 19:55


NVD link : CVE-2020-26303

Mitre link : CVE-2020-26303

CVE.ORG link : CVE-2020-26303


JSON object : View

Products Affected

bevacqua

  • insane
CWE
CWE-1333

Inefficient Regular Expression Complexity