CVE-2026-9769
justhtml before 1.10.0 Denial of Service via deeply nested HTML
justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() construction, TreeBuilder.finish() unconditionally calls _populate_selectedcontent(), which recursively traverses the DOM tree via _find_elements()/_find_element() without a depth bound. An attacker who can supply HTML for parsing can provide deeply nested elements (e.g., ~1000 nested <div> tags, roughly 11 KB) to exceed CPython's default recursion limit and trigger an unhandled RecursionError, which may abort parsing, fail requests, or terminate a worker/process depending on the host application's exception handling.
| CWE | CWE-674 |
| Vendor | emilstenstrom |
| Product | justhtml |
| Published | Aug 23, 2026 |
Get instant alerts for emilstenstrom justhtml
Be the first to know when new high vulnerabilities affecting emilstenstrom justhtml are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H