Loading
Generated remediation guidance and an executive summary. No account required.
Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacker to bypass hostname whitelist validation set by the "allowedIframeHostnames" option.
Use Apostrophecms vendor hub and Sanitize-Html product page to widen CVE-2021-26539 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-40186, CVE-2014-125128 and CVE-2019-25225 for nearby disclosures in the same product family.