cve/2024/CVE-2024-34078.md
2024-05-25 21:48:12 +02:00

923 B

CVE-2024-34078

Description

html-sanitizer is an allowlist-based HTML cleaner. If using keep_typographic_whitespace=False (which is the default), the sanitizer normalizes unicode to the NFKC form at the end. Some unicode characters normalize to chevrons; this allows specially crafted HTML to escape sanitization. The problem has been fixed in 2.4.2.

POC

Reference

No PoCs from references.

Github