lowVulnerability

GHSA-r8cj-3554-33mr

## Summary `justhtml` `1.18.0` fixes multiple low-severity denial-of-service hardening issues in CSS selector handling and linkification. These issues are availability concerns. They do not allow script execution, data disclosure, or sanitizer bypass by themselves. ## Affected versions - `justhtml` `< 1.18.0` ## Fixed version - `justhtml` `1.18.0` released on May 4, 2026 ## Impact ### CSS selector handling Applications that evaluate attacker-controlled selector strings, or that run selector-based transform pipelines over attacker-controlled documents, could consume disproportionate CPU or memory. The affected selector patterns included oversized selectors, large selector lists, oversized compound selectors, long combinator chains, deeply nested functional pseudo-classes such as `:not(...)`, repeated attribute/class token matching over large values, repeated sibling or ancestor scans, repeated positional pseudo-class work, and `:contains(...)` over large descendant text. Programmatically constructed malformed DOM graphs could also trigger non-terminating or duplicate traversal in some selector paths, including cyclic/shared child graphs, cyclic parent chains, and cyclic text traversal for `:contains(...)`. ### Linkification Attacker-controlled text containing punctuation-heavy input or URL candidates ending in long runs of unmatched closing brackets could cause repeated rescanning and consume disproportionate CPU when linkification was enabled. ## Default configuration Ordinary sanitization of parsed HTML with the default `JustHTML(..., sanitize=True)` configuration is not expected to expose untrusted users to selector injection, because selectors are normally supplied by application code. The main risk areas are: - applications that accept selector strings from untrusted users and pass them to `query(...)`, `matches(...)`, or selector-based transforms - custom transform or sanitization pipelines that run selector matching over very large untrusted d

Properties

ghsa_id
GHSA-r8cj-3554-33mr
summary
justhtml introduces denial-of-service hardening
severity
low
cve_id
GHSA-r8cj-3554-33mr
is_ghsa_only
true
ghsa_published
2026-05-08T18:19:30Z
source_url
https://github.com/advisories/GHSA-r8cj-3554-33mr
ghsa_updated
2026-05-08T18:19:31Z

Related Entities (6)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]pip/justhtml

AFFECTS (1)

[Software]pip/justhtml

HAS_WEAKNESS (3)

[Weakness]Uncontrolled Resource Consumption
[Weakness]Loop with Unreachable Exit Condition ('Infinite Loop')
[Weakness]Inefficient Algorithmic Complexity

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-r8cj-3554-33mr — Ninja Signal Threat Intelligence | Ninja Signal