high
CVE-2026-4671
justhtml CSS selector and linkification denial of service
- Severity
- high
- Affected product
- justhtml
- Affected versions
- justhtml < 1.18.0
- Fixed in
- justhtml 1.18.0
- Added to NewScan
- 2026-08-23
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints justhtml from its response and reports this CVE when the detected version falls inside the affected range below.
Version-match only: the existing requirements.txt parser supplies the exact justhtml pin. Selector and linkification stress inputs are not sent because timing-based checks are not reproducible.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →