Description
insane is a whitelist-oriented HTML sanitizer. Versions 2.6.2 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 2.6.2
References
Could your website be exposed too?
SmartScanner can check your website for insane vulnerable to Regular Expression Denial of Service and gives you actionable findings to investigate.
Start a free scanRelated Issues
- glob-parent vulnerable to Regular Expression Denial of Service in enclosure regex - CVE-2020-28469
- is_js vulnerable to Regular Expression Denial of Service - CVE-2020-26302
- steal vulnerable to Regular Expression Denial of Service via input variable - CVE-2022-37260
- path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters - CVE-2026-4867


