📦 Java Html Sanitizer

by Owasp

🔍 What is Java Html Sanitizer?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-42575

CRITICAL CVSS 9.8 Oct 18, 2021

CVE-2021-42575 is a critical vulnerability in the OWASP Java HTML Sanitizer that allows bypassing HTML sanitization policies for SELECT, STYLE, and OPTION elements. This enables cross-site scripting (...

CVE-2025-66021

MEDIUM CVSS 6.1 Nov 26, 2025

This vulnerability in OWASP Java HTML Sanitizer allows cross-site scripting (XSS) attacks when the HtmlPolicyBuilder configuration permits noscript and style tags with allowTextIn inside style tags. A...