github cure53/DOMPurify 2.5.1
DOMPurify 2.5.1

latest releases: 3.1.3, 2.5.3, 3.1.2...
16 days ago
  • Fixed an mXSS sanitizer bypass reported by @icesfont
  • Added new code to track element nesting depth
  • Added new code to enforce a maximum nesting depth of 255
  • Added coverage tests and necessary clobbering protections

Note that this is a security release and should be upgraded to immediately. Please also note that further releases may follow as the underlying vulnerability is apparently new and further variations may be discovered.

Don't miss a new DOMPurify release

NewReleases is sending notifications on new releases.