Known Vulnerabilities
CVE-2024-45338
An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This could cause a denial of service.
MEDIUM
CVSS 5.3
Published Dec 18, 2024
CVE-2023-3978
Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack.
UNKNOWN
Published Aug 02, 2023