Description
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Certain configurations of rails-html-sanitizer < 1.4.4 use an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes. This may lead to a denial of service through CPU resource consumption. This issue has been patched in version 1.4.4.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3566-1 | ruby-rails-html-sanitizer security update |
Debian DLA |
DLA-3902-1 | ruby-rails-html-sanitizer security update |
EUVD |
EUVD-2022-7520 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Certain configurations of rails-html-sanitizer < 1.4.4 use an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes. This may lead to a denial of service through CPU resource consumption. This issue has been patched in version 1.4.4. |
Github GHSA |
GHSA-5x79-w82f-gw8w | Inefficient Regular Expression Complexity in rails-html-sanitizer |
References
History
Mon, 03 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 19 Nov 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-03T21:45:57.498Z
Reserved: 2022-01-19T21:23:53.778Z
Link: CVE-2022-23517
Updated: 2025-11-03T21:45:57.498Z
Status : Modified
Published: 2022-12-14T17:15:10.130
Modified: 2025-11-03T22:15:56.397
Link: CVE-2022-23517
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Github GHSA