First published: Wed Aug 09 2023(Updated: )
### Impact lol-html can cause panics on certain HTML inputs. Anyone processing arbitrary 3rd party HTML with the library is affected. ### Patches The problem has been patched and released as v1.1.1 ### Workarounds No workarounds exist.
Credit: cna@cloudflare.com cna@cloudflare.com cna@cloudflare.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cloudflare Lol-html | <1.1.1 | |
rust/lol-html | <1.1.1 | 1.1.1 |
<1.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-4241 is high with a severity value of 7.5.
CVE-2023-4241 can cause panics on certain HTML inputs, affecting anyone processing arbitrary 3rd party HTML with the lol-html library.
Yes, CVE-2023-4241 has been patched and released as v1.1.1 of the lol-html library.
No, there are no workarounds for CVE-2023-4241.
You can find more information about CVE-2023-4241 on the following references: [GitHub Advisory](https://github.com/cloudflare/lol-html/security/advisories/GHSA-c3x7-354f-4p2x), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-4241), [GitHub Advisory (GHSA-c3x7-354f-4p2x)](https://github.com/advisories/GHSA-c3x7-354f-4p2x).