Loading
Generated remediation guidance and an executive summary. No account required.
The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment removal.
Use CWE-1333, Apostrophecms vendor hub and Sanitize-Html product page to widen CVE-2022-25887 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-40186, CVE-2014-125128 and CVE-2019-25225 for nearby disclosures in the same product family.