Unhead has a hasDangerousProtocol() bypass via leading-zero padded HTML entities in useHeadSafe()
- Severity:
- Medium
Description
##EVIDENCE
<img width=”1919” height=”947” alt=”Screenshot_2026-03-25_090715” src=”https://github.
Recommendation
Update the unhead package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.1.13
- Patched version(s): 2.1.13
References
Related Issues
- Unhead has XSS bypass in `useHeadSafe` via attribute name injection and case-sensitive protocol check - CVE-2026-31860
- sanitize-html allowedTags Bypass via Entity-Decoded Text in nonTextTags Elements - CVE-2026-40186
- LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS - CVE-2026-44644
- LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body - CVE-2026-44645
You might also like:
- Tags:
- npm
- unhead
Anything's wrong? Let us know Last updated on April 09, 2026


