justhtml 1.15.0 includes multiple security fixes affecting URL sanitization helpers, HTML serialization, Markdown passthrough, and several custom sanitization-policy edge cases.
These issues have different impact levels and do not all affect the default configuration in the same way.
justhtml <= 1.14.0justhtml 1.15.0 released on April 9, 2026These issues could affect applications using JustHTML helpers or programmatic DOM construction, even outside the default HTML sanitization path.
JustHTML.clean_url_value(...) and clean_url_in_js_string(...) could accept URL values such as javascript:..., which became active javascript: URLs after HTML attribute parsing.\\evil.example/x or /\\evil.example/x as safe relative URLs even though browsers could resolve them as remote requests.https://[evil.example]/x could raise exceptions and crash sanitization when host allowlists were used.--> could break out of the comment and inject live markup.to_markdown(html_passthrough=True) could reintroduce active HTML from sanitized <textarea> content by emitting a raw closing </textarea> sequence.These issues affected custom policies more than the default safe configuration.
a[ping] was handled as a single URL even though browsers interpret it as a space-separated URL list.attributionsrc was not treated as URL-bearing and could preserve attacker-controlled reporting endpoints.link[imagesrcset] was not treated as URL-bearing and could preserve attacker-controlled image candidates.<meta http-equiv="refresh"> tags could keep redirect targets without URL-policy enforcement.<base href> tags could rewrite how later relative URLs resolved in the browser.<style> blocks could keep resource-loading CSS such as @import, url(...), or image-set(...).DropAttrs(...), DropUrlAttrs(...), AllowStyleAttrs(...), and MergeAttrs(...).Most of the custom-policy issues above did not affect the default JustHTML(..., sanitize=True) behavior.
The main exceptions were:
clean_url_value(...)html_passthrough=TrueUpgrade to justhtml 1.15.0.
If you cannot upgrade immediately:
html_passthrough=True for untrusted content<style>, <meta http-equiv="refresh">, and <base href> in custom policiesping, attributionsrc, or imagesrcset unless you explicitly validate them{
"cwe_ids": [
"CWE-178",
"CWE-20",
"CWE-755",
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2026-04-10T19:20:04Z",
"nvd_published_at": null,
"severity": "MODERATE"
}