Inefficient Algorithmic Complexity in Java HTML Sanitizer - #VU152249
Published: September 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity in the CSS lexer when processing a run of unmatched close brackets after a run of open brackets. A remote attacker can submit CSS containing a long sequence of open brackets followed by unmatched close brackets to cause a denial of service.