Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.7
JustHTML Denial of Service via Recursion
published 11 days ago
Summary
JustHTML versions 1.9.1 and earlier can crash or fail when processing deeply nested HTML input. This can cause a denial of service if not handled properly. Update to version 1.9.2 or later to fix this issue.
What to do
- Update justhtml to version 1.10.0.
- Update emilstenstrom justhtml to version 1.10.0 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| PyPI | – | justhtml |
< 1.10.0 Fix: upgrade to 1.10.0
|
| – | emilstenstrom | justhtml | < 1.10.0 |
Original advisory text
justhtml before 1.10.0 Denial of Service via deeply nested HTML
justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() construction, TreeBuilder.finish() unconditionally calls _populate_selectedcontent(), which recursively traverses the DOM tree via _find_elements()/_find_element() without a depth bound. An attacker who can supply HTML for parsing can provide deeply nested elements (e.g., ~1000 nested <div> tags, roughly 11 KB) to exceed CPython's default recursion limit and trigger an unhandled RecursionError, which may abort parsing, fail requests, or terminate a worker/process depending on the host application's exception handling.
Severity
8.7
High
CVSS 4.0: 8.3 (OSV)
Type
CWE-674Uncontrolled Recursion
Timeline
Published23 Aug 2026
Updated24 Aug 2026
First seen17 Mar 2026
Sources
GHSA-v7cf-c9rm-wm3j · OSV
Monitor software like this
Free during beta