CVE-2026-25543: Htmlsanitizer Project Htmlsanitizer

Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.

HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. Prior to versions 9.0.892 and 9.1.893-beta, if the template tag is allowed, its contents are not sanitized. The template tag is a special tag that does not usually render its contents, unless the shadowrootmode attribute is set to open or closed. This issue has been patched in versions 9.0.892 and 9.1.893-beta.

Affected products

  • Htmlsanitizer Project Htmlsanitizer: before 9.0.892 (fixed in 9.0.892); from 9.1.878, before 9.1.893 (fixed in 9.1.893)

Published 2026-02-04. Last modified 2026-06-17.