critical
CVE-2026-7808
justhtml HTML sanitization bypass permits dangerous active content
- Severity
- critical
- Affected product
- justhtml
- Affected versions
- justhtml < 1.16.0
- Fixed in
- justhtml 1.16.0
- Added to NewScan
- 2026-08-23
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints justhtml from its response and reports this CVE when the detected version falls inside the affected range below.
Version-match only: `analyze_technologies` reads exact justhtml pins from an exposed pip requirements.txt. CVE-2026-7808 affects releases before 1.16.0; do not actively submit dangerous HTML to a customer application.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →