{"id":"CVE-2026-25543","summary":"HtmlSanitizer has a bypass via template tag","details":"HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. Prior to versions 9.0.892 and 9.1.893-beta, if the template tag is allowed, its contents are not sanitized. The template tag is a special tag that does not usually render its contents, unless the shadowrootmode attribute is set to open or closed. This issue has been patched in versions 9.0.892 and 9.1.893-beta.","aliases":["GHSA-j92c-7v7g-gj3f"],"modified":"2026-08-12T03:51:08.142843366Z","published":"2026-02-04T21:45:25.665Z","database_specific":{"cwe_ids":["CWE-116"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25543.json","unresolved_ranges":[{"extracted_events":[{"fixed":"9.1.893-beta"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://www.nuget.org/packages/HtmlSanitizer/9.0.892"},{"type":"WEB","url":"https://www.nuget.org/packages/HtmlSanitizer/9.1.893-beta"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25543.json"},{"type":"ADVISORY","url":"https://github.com/mganss/HtmlSanitizer/security/advisories/GHSA-j92c-7v7g-gj3f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25543"},{"type":"FIX","url":"https://github.com/mganss/HtmlSanitizer/commit/0ac53dca30ddad963f2b243669a5066933d82b81"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mganss/htmlsanitizer","events":[{"introduced":"0"},{"fixed":"0ac53dca30ddad963f2b243669a5066933d82b81"}],"database_specific":{"cpe":"cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"9.0.892"}],"source":["AFFECTED_FIELD","CPE_RANGE","REFERENCES"]}}],"versions":["v9.0.889","v9.0.886","v9.0.884","v9.0.881","v9.0.876","v9.0.873","v8.1.870","v8.0.865","v8.0.843","v8.0.838","v8.0.811","v8.0.795","v8.0.746","v8.0.744","v8.0.723","v8.0.718","v8.0.692","v8.0.645","v8.0.601","v7.1.542","v7.1.512","v7.1.509","v7.1.488","v7.1.475","v7.0.473","v7.0.470","v6.0.453","v6.0.441","v6.0.437","v6.0.430","v6.0.423","v6.0.409","v5.0.395","v5.0.392","v5.0.391","v5.0.388","v5.0.385","v5.0.382","v5.0.379","v5.0.376","v5.0.372","v5.0.371","v5.0.368","v5.0.367","v5.0.366","v5.0.365","v5.0.364","v5.0.363","v5.0.358","v5.0.355","v5.0.354","v5.0.343","v5.0.342","v5.0.332","v5.0.331","v5.0.328","v5.0.325","v5.0.322","v5.0.319","v5.0.316","v5.0.313","v5.0.310","v5.0.307","v5.0.304","v5.0.303","v5.0.298","v5.0.297","v5.0.296","v5.0.293","v5.0.292","v5.0.291","v5.0.290","v5.0.287","v5.0.283","v5.0.280","v5.0.277","v5.0.274","v5.0.272","v5.0.269","v5.0.266","v5.0.263","v5.0.260","v5.0.257","v5.0.250","v5.0.249","v5.0.248","v5.0.245","v5.0.244","v5.0.239","v5.0.236","v5.0.233","v4.0.230","v4.0.229","v4.0.228","v4.0.219","v4.0.217","v4.0.212","v4.0.211","v4.0.210","v4.0.209","v4.0.207","v4.0.205","v4.0.204","v4.0.201","v4.0.199","v4.0.193","v4.0.192","v4.0.191","v4.0.189","v4.0.188","v4.0.187","v4.0.186","v4.0.185","v4.0.183","v4.0.182","v4.0.181","v4.0.180","v4.0.179","v3.5.169-beta","v3.5.168-beta","v3.5.167-beta","v3.4.156","v3.4.152-beta","v3.3.148-beta","v3.3.147-beta","v3.3.146-beta","v3.3.145-beta","v3.3.144-beta","v3.3.143-beta","v3.3.142","v3.3.140-beta","v3.3.134-beta","v3.3.132-beta","v3.3.131-beta","v3.3.130-beta","v3.3.129-beta","v3.3.128-beta","v3.3.127-beta","v3.3.126-beta","v3.3.125-beta","v3.3.122-beta","v3.2.105","v3.2.103","v3.2.100","v3.1.98","v3.1.93","v3.1.91","v3.1.79","v3.1.76"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-25543.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}]}