« Volver al listado

CVE-2026-68750

Estado: ModificadaAlta (8.2)—

Inefficient Algorithmic Complexity vulnerability in the traversal engine in rrrene html_sanitize_ex allows an unauthenticated remote attacker to exhaust server CPU and memory via a flat run of sibling elements in sanitized HTML. The list clause of HtmlSanitizeEx.Traverser.traverse/2 recurses on the tail of a sibling list and then evaluates List.flatten([head] ++ tail) over the already flattened result, so every one of n siblings copies and re-walks the entire remaining tail. The flattening is only needed for the rare case where scrub returns several replacement nodes for one node, but the cost is paid across the whole tail at every step, making traversal quadratic in sibling count.

Leer descripción completaMostrar menos

The traverser sits on every public entry point, so no particular scrubber or configuration is required and the payload needs only allowed tags. A 160 KB body of 20,000 sibling elements occupies a scheduler for roughly 1.7 seconds, and the cost grows faster than the body does.

This issue affects html_sanitize_ex: from 0.3.1 before 1.4.5 and from 1.5.0-rc.0 before 1.5.3.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vector CVSS AV:N/AC:L sin autenticación indica explotación remota (T1190). CWE-407 y descripción explícita de agotamiento de CPU/memoria por traversal cuadrático → DoS algorítmico (T1499.004).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-68750",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-68750",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-08-06T15:41:21.489983Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 8.2,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "PRESENT",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "NONE",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "HIGH",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "NONE",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:rrrene:html_sanitize_ex:*:*:*:*:*:*:*:*"
          ],
          "repo": "https://github.com/rrrene/html_sanitize_ex",
          "vendor": "rrrene",
          "modules": [
            "'Elixir.HtmlSanitizeEx.Traverser'",
            "'Elixir.HtmlSanitizeEx'"
          ],
          "product": "html_sanitize_ex",
          "versions": [
            {
              "status": "affected",
              "version": "0.3.1",
              "lessThan": "1.4.5",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "1.5.0-rc.0",
              "lessThan": "1.5.3",
              "versionType": "semver"
            }
          ],
          "packageURL": "pkg:hex/html_sanitize_ex",
          "packageName": "html_sanitize_ex",
          "programFiles": [
            "lib/html_sanitize_ex/traverser.ex",
            "lib/html_sanitize_ex.ex"
          ],
          "collectionURL": "https://repo.hex.pm",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "'Elixir.HtmlSanitizeEx.Traverser':traverse/2"
            },
            {
              "name": "'Elixir.HtmlSanitizeEx':basic_html/1"
            },
            {
              "name": "'Elixir.HtmlSanitizeEx':html5/1"
            },
            {
              "name": "'Elixir.HtmlSanitizeEx':markdown_html/1"
            },
            {
              "name": "'Elixir.HtmlSanitizeEx':strip_tags/1"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:rrrene:html_sanitize_ex:*:*:*:*:*:*:*:*"
          ],
          "repo": "https://github.com/rrrene/html_sanitize_ex",
          "vendor": "rrrene",
          "modules": [
            "'Elixir.HtmlSanitizeEx.Traverser'",
            "'Elixir.HtmlSanitizeEx'"
          ],
          "product": "html_sanitize_ex",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "9f5ccedbed230930813f992a1e6906fcf485981e",
                  "status": "unaffected"
                },
                {
                  "at": "507a6fb95dd4c466cac8a8355d8989043e9fbcc1",
                  "status": "unaffected"
                }
              ],
              "version": "69ea11d61525c470b39b6860d024770d5573ff1f",
              "lessThan": "*",
              "versionType": "git"
            }
          ],
          "packageURL": "pkg:github/rrrene/html_sanitize_ex",
          "packageName": "rrrene/html_sanitize_ex",
          "programFiles": [
            "lib/html_sanitize_ex/traverser.ex",
            "lib/html_sanitize_ex.ex"
          ],
          "collectionURL": "https://github.com",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "'Elixir.HtmlSanitizeEx.Traverser':traverse/2"
            },
            {
              "name": "'Elixir.HtmlSanitizeEx':basic_html/1"
            },
            {
              "name": "'Elixir.HtmlSanitizeEx':html5/1"
            },
            {
              "name": "'Elixir.HtmlSanitizeEx':markdown_html/1"
            },
            {
              "name": "'Elixir.HtmlSanitizeEx':strip_tags/1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-08-06T16:16:51.907",
  "references": [
    {
      "url": "https://cna.erlef.org/cves/CVE-2026-68750.html",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://github.com/rrrene/html_sanitize_ex/commit/507a6fb95dd4c466cac8a8355d8989043e9fbcc1",
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://github.com/rrrene/html_sanitize_ex/commit/9f5ccedbed230930813f992a1e6906fcf485981e",
      "tags": [
        "Patch"
      ],
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://github.com/rrrene/html_sanitize_ex/security/advisories/GHSA-463q-p2fr-mh9p",
      "tags": [
        "Broken Link"
      ],
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://osv.dev/vulnerability/EEF-CVE-2026-68750",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
      "description": [
        {
          "lang": "en",
          "value": "CWE-407"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Inefficient Algorithmic Complexity vulnerability in the traversal engine in rrrene html_sanitize_ex allows an unauthenticated remote attacker to exhaust server CPU and memory via a flat run of sibling elements in sanitized HTML. The list clause of HtmlSanitizeEx.Traverser.traverse/2 recurses on the tail of a sibling list and then evaluates List.flatten([head] ++ tail) over the already flattened result, so every one of n siblings copies and re-walks the entire remaining tail. The flattening is only needed for the rare case where scrub returns several replacement nodes for one node, but the cost is paid across the whole tail at every step, making traversal quadratic in sibling count.\n\nThe traverser sits on every public entry point, so no particular scrubber or configuration is required and the payload needs only allowed tags. A 160 KB body of 20,000 sibling elements occupies a scheduler for roughly 1.7 seconds, and the cost grows faster than the body does.\n\nThis issue affects html_sanitize_ex: from 0.3.1 before 1.4.5 and from 1.5.0-rc.0 before 1.5.3."
    }
  ],
  "lastModified": "2026-08-19T12:18:35.400",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:rrrene:htmlsanitizeex:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DE85053C-AE84-4570-A90C-4D4CCD7A4BA3",
              "versionEndExcluding": "1.5.3",
              "versionStartIncluding": "0.3.1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
}