Skip to content

DOMPurify 2.5.1

Compare
Choose a tag to compare
@cure53 cure53 released this 26 Apr 11:11
· 27 commits to 2.x since this release
f275c0b
  • Fixed an mXSS sanitizer bypass reported by @icesfont
  • Added new code to track element nesting depth
  • Added new code to enforce a maximum nesting depth of 255
  • Added coverage tests and necessary clobbering protections

Note that this is a security release and should be upgraded to immediately. Please also note that further releases may follow as the underlying vulnerability is apparently new and further variations may be discovered.