Loading HuntDB...

GHSA-c3x7-354f-4p2x

GitHub Security Advisory

lol-html panics on certain HTML inputs

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

### Impact
lol-html can cause panics on certain HTML inputs. Anyone processing arbitrary 3rd party HTML with the library is affected.

### Patches
The problem has been patched and released as v1.1.1

### Workarounds
No workarounds exist.

Affected Packages

crates.io lol-html
Affected versions: 0 (fixed in 1.1.1)

Related CVEs

Key Information

GHSA ID
GHSA-c3x7-354f-4p2x
Published
August 9, 2023 1:17 PM
Last Modified
August 9, 2023 1:17 PM
CVSS Score
7.5 /10
Primary Ecosystem
crates.io
Primary Package
lol-html
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 12, 2025 6:34 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.