Releases: OWASP/java-html-sanitizer
Release list
Release 20260924.2
Changelog
- 2e944e7 Release version 20260924.2 (GitHub Actions)
- b203767 Add the change log entry for 20260924.2 (Jim Manico)
- 9b3233d Make the denial-of-service invariant promise what can be kept (Jim Manico)
- dfe357e Take the review: size the churn test for an ordinary heap (Jim Manico)
- 4c910d3 Take the review: keep the walk's guard, drop the dead growth cap (Jim Manico)
- f95efad Take the review: say the depth scan's over-count can drop valid CSS (Jim Manico)
- de57cff Take the review: count open brackets in three ints, not 126 (Jim Manico)
- cf9567f Take the review: make the depth scan's marking plain to read (Jim Manico)
- 33e8d34 Prepare for next development version (GitHub Actions)
- afac176 Record GHSA-x6fc-6qh4-g3wr (Jim Manico)
Contributors
We'd like to thank the following people for their contributions:
- Jim Manico
Release 20260924.1
Changelog
- 4fd25f3 Release version 20260924.1 (GitHub Actions)
- 1231831 Take the review: mark function depths in a plain array, not a BitSet (Jim Manico)
- 82e9b10 Add the denial-of-service invariant to AGENTS.md (Jim Manico)
- d0b06bd Drop an unmatched CSS close bracket in constant time (Jim Manico)
- 8a55b77 Drop CSS declarations that nest functions deeper than sixteen (Jim Manico)
- a310fe4 Harden release and build verification (Jim Manico)
- 3b122bb Record GHSA-6rfr-g8xv-xrp3 (Jim Manico)
- 393d86d Prepare for next development version (GitHub Actions)
Contributors
We'd like to thank the following people for their contributions:
- Jim Manico
Release 20260922.1
Changelog
- c2042c0 Release version 20260922.1 (GitHub Actions)
- ea86ffa Encode CSS URL content after rewriting (Jim Manico)
- de7555c Record GHSA-vqwm-jvq2-mfwc and pin its reported cases (Jim Manico)
- 0261fc6 Prepare for next development version (GitHub Actions)
Contributors
We'd like to thank the following people for their contributions:
- Jim Manico
Release 20260921.1
Changelog
- b8d90c9 Release version 20260921.1 (GitHub Actions)
- 37d9212 Preserve form text policy across implied tables (Jim Manico)
- 7ae2b5c Stabilize list-item closure across output contexts (Jim Manico)
- 9059be1 Preserve text after an ignored form in a dropped table (Jim Manico)
- 27d2c04 Preserve nested list context for browser tree stability (Jim Manico)
- 1901496 Cover dropped-template list residuals (Jim Manico)
- 0a55504 Stabilize list contexts after dropped wrappers (Jim Manico)
- 6e0254c Stabilize text after bare dropped-table parts (Jim Manico)
- 7b4e234 Take the review: keep select retirement synchronized and scoped (Jim Manico)
- 50a7d01 Fix browser-round-trip text gates for #497 (Jim Manico)
- 9ebd255 Take the review: keep the rule to the container, not to table scope (Jim Manico)
- 6469377 Take the third review: keep the formatting a browser keeps, and say what changed (Jim Manico)
- ee953d2 Take the second review: judge every barrier by the output, keep the option's item (Jim Manico)
- afe8e8e Take the review: bound the resumption queue, judge barriers by the output (Jim Manico)
- 2a9ede4 Take the probe: do not resume formatting inside an element read as raw text (Jim Manico)
- a9f9abb Close the open list item for a list item start tag, through formatting (Jim Manico)
- f9a0c87 Take the review: a dropped template bounds no table scope, and holds a col directly too (Jim Manico)
- 24c6c78 Give a caption or column group under a dropped template its table in Sanitizers.TABLES (Jim Manico)
- 8b6c865 Take the second review: push the table out from below the dropped entries (Jim Manico)
- 2560fc8 Take the probe: stop the select's scan at the select's own logical item (Jim Manico)
- 1cb96ab Take the review: judge the select's place by the nearest emitted ancestor, keep the dropped cell's end tag (Jim Manico)
- ec40ba1 Take the third review: the output decides an element's containment under a known root (Jim Manico)
- 2c5a5c6 Keep item 2 out: judge only an option under a dropped template here (Jim Manico)
- 3120ddc Take the probe: an option under a dropped template inside a table gets a foster-parented select (Jim Manico)
- 61c3ffe Take the probe: forward foreign table parts only while the input names a root, outside raw-text nodes (Jim Manico)
- d8c9c25 Take the review: judge a dropped template's parts in the output, foster-parent the select out of a kept table (Jim Manico)
- 3d02eb5 Take the second review: forward foreign table parts, no select for a foreign option (Jim Manico)
- 16e9003 Take the probe: keep the table parts' wrappers as they were, judge parts under a dropped template where it stood (Jim Manico)
- 780c355 Apply the free wrappers under every container past the wrapper's set (Jim Manico)
- e07877a Take the probe: keep HTML containment for a raw-text-named foreign node (Jim Manico)
- b75252a Take the review: bound the root by what the parsers still have open (Jim Manico)
- 4aff8a1 Take the review: leave more of a document behind before the throw (Jim Manico)
- 9a1979e Judge content below the foreign root as in a fresh body (Jim Manico)
- 74d8e25 Test that openDocument resets what a throwing receiver left open (Jim Manico)
- 6dba384 Keep the list's implied item out of a forwarded foreign root (Jim Manico)
- a750b4a Take the review: let the select's item through the limit check (Jim Manico)
- 10c8952 Never emit the list item implied for content a select cannot hold (Jim Manico)
- fd0fd4c Take the review: open a suppressed option's policy entry under its canonical name (Jim Manico)
- b5f6bca Document the nesting limit's exception and report dropped tags under one name (Jim Manico)
- 6c1fb9f Take the review: forget a queued formatting element its end tag or a new link ends (Jim Manico)
- bd1bf23 Take the review: keep disallowed text out of the element a suppressed part lands in (Jim Manico)
- cfb21b6 Take the review: index the output names that bound a form's table scope (Jim Manico)
- 3387e8c Take the review: do not resume formatting around a wrapper implied for a tag (Jim Manico)
- cf8bad6 Take the review: keep cell text of a dropped table in an integration point (Jim Manico)
- c772698 Take the review: forward a dropped foreign root's children beside a table (Jim Manico)
- eb11921 Take the review: keep a dropped select's options out of an implied list item (Jim Manico)
- 33c2b90 Take the review: replay a form's start decision at its end tag (Jim Manico)
- f2fc154 Take the review: do not spend the nesting budget on dropped unknown tags (Jim Manico)
- f043355 Take the review: reset the two fields the document lifecycle missed (Jim Manico)
- adf82d8 Take the review: report a form start ignored for the form pointer (Jim Manico)
- 51e5a35 Take the review: skip the outputless-table scans when no table is marked (Jim Manico)
- 462adc5 Take the review: assert the browser's view of content around table forms (Jim Manico)
- 2c2d2bf Take the review: keep text that lands beside a retired output table (Jim Manico)
- 147f3fa Take the review: keep the table open for a form in a dropped row group (Jim Manico)
- 350cc3a Take the review: leave a foreign root in place outside table modes (Jim Manico)
- 58dd112 Take the review: latch the form pointer only for a form that is emitted (Jim Manico)
- 16e132d Take the review: answer the balancer from the policy behind a listener (Jim Manico)
- 756d10c Take the review: forward unrecognized starts under their canonical name (Jim Manico)
- f3f4406 Take the review: count forwarded elements toward the nesting limit (Jim Manico)
- 19b5fd2 Judge formatting resumption by the insertion point, not by the tag (Jim Manico)
- bceeb7f Do not resume formatting where content is inserted under foreign rules (Jim Manico)
- e92ffb3 Forget forwarded elements inside a suppressed option by count, not depth (Jim Manico)
- 6fd3a1f Close popped foreign elements by identity and balance forwarded elements (Jim Manico)
- 69cde7e Track form pointer, foreign and template contexts for #484 review fixes (Jim Manico)
- 14e4d29 Handle forms in table insertion modes (Jim Manico)
- a75248f Preserve text gates in renamed literal elements (Goutam Adwant)
- 5fab8e6 docs: clarify module guides and improve navigation (Jim Manico)
- d170ec1 docs: add module README guides (Jim Manico)
- 94a3a6c Balance table parts outside their context (Jim Manico)
- 2356e1f Close elements emitted at the nesting limit (Jim Manico)
- 705b331 Preserve custom policy reporter compatibility (Jim Manico)
- 3240a05 Fix table foster-parenting edge cases (Jim Manico)
- 77fc910 Judge pushed-out content by the element that holds the table (Jim Manico)
- 6025077 Stop the return to a pushed-out table at a table-scope boundary (Jim Manico)
- b93f7b6 Keep a table open across content a browser would put in front of it (Jim Manico)
- a59c4e6 Report the renderer's tag and attribute drops to HtmlChangeListener (Jim Manico)
- 5a9d28b Judge a renamed element by the name the author wrote (Jim Manico)
- 99764a3 Fix stale Javadoc link to the renamed foreign-content root set (Jim Manico)
- 669b266 Rework the literal-text tag filter for fidelity and footprint (Jim Manico)
- c62be95 Fix review follow-ups for literal content and links (Jim Manico)
- 599af06 Close two more ways past the literal-text filter, and back it in the renderer (Jim Manico)
- 3d617f3 Report policy-filtered literal text to listeners (Jim Manico)
- 0ac7b29 Fail closed for an open dialog like search in foreign content (Jim Manico)
- 07cb81b Take the review: the comment element is not literal content (Jim Manico)
- b83b617 Drop a tag the input ends inside; read "</" plus a non-letter as a comment (Jim Manico)
- 86cfa80 Wrap a test line to 80 columns (Jim Manico)
- 7b06316 Stop a link inside a table cell from ending a link outside the table (Jim Manico)
- 430cadc Take the review: bind the text hook per document, see through wrappers (Jim Manico)
- 95ba82f Strip every tag from the text of kept literal-content elements (Jim Manico)
- f9819fa Fix foreign-content tracker gaps found in review (Jim Manico)
- 2eeecfa Tidy pre-existing javadoc errors and over-long lines (Jim Manico)
- e236121 Report emptied elements' attributes, their values, and dropped text (Jim Manico)
- 5a5c0c6 Track HTML stack mutations in foreign content (Jim Manico)
- b7936a9 Record the widened authority rejection and bound the relative-only reach (Jim Manico)
- 9e05566 Fail closed when an HTML end tag's effect on foreign content is unknown (Jim Manico)
- 4ed47ef Reject browser-equivalent URL authorities (Jim Manico)
- c7d8455 Update AGENTS.md (Jim Manico)
- 192a0e8 Add an explicit relative-only URL policy (Jim Manico)
- eb1d986 Document where the URL protocol guard runs relative to author policies (Jim Manico)
- 0308408 Close foreign content on the end tag of an enclosing HTML element (Jim Manico)
- 2f2d53f Track parser context for foreign self-closing tags (Jim Manico)
- 02a0ce1 Honor the self-closing flag on start tags inside svg and math (Jim Manico)
- 3cd7853 Add a JPMS module descriptor in META-INF/versions/9 (Jim Manico)
- c920a45 Let the default URL protocol guard yield in PolicyFactory.and (Jim Manico)
- fa404e0 Add AGENTS.md guidance for AI-assisted work (Jim Manico)
- 176d6a6 Take the review: constant-time gate, and disallowTextIn wherever x appears (Jim Manico)
- f9e8977 Gate text by its enclosing elements, and honour disallowTextIn on dropped ones (Jim Manico)
- b701e1a Report a renamed element as kept, not discarded (Jim Manico)
- 3a55b6b Restore the brace the merge dropped between two test blocks (Jim Manico)
- b7bf310 Let contain what browsers put in template.content (Jim Manico)
- 6d712ce Stop PolicyFactory from retaining the builder that made it (Jim Manico)
- 5395a45 Take the review: list Dependabot directories, cover both matching arms (Jim Manico)
- 413b35a Cover matching(Predicate) here, and configure Dependabot for new modules (Jim Manico)
- f1d6b62 Correct the examples ...
Release 20260313.1
Changelog
- 4e186b8 Release version 20260313.1 (GitHub Actions)
- 3dc7b8e Add SECURITY.md to RELEASE-checklist.sh (Sven Strickroth)
- 2e49088 Update SECURITY.md for 20260103.1 (Sven Strickroth)
- e48c0e3 Preserve order of rel attributes (#336) (strangelookingnerd)
- f6a4ed1 Fix invalid nested when sanitizing (Shangeeth Rajasekar) 21dcaa0 Add CVE-2025-66021 vulnerability information (Melloware) 1532735 Update badges in readme (Andres Almiray) 95b0261 Update release workflow (Andres Almiray) cda3636 Prepare for next development version (GitHub Actions) 2783897 Release version 20260102.1 (GitHub Actions) f40152f Update release configuration (Andres Almiray) c159aac fixes examples broken link (Sergio del Amo) dea5672 Fix #369: Ensure owasp-java-html-sanitizer targets Java 8 (Andres Almiray) 66b55e0 Configure release announcements (Andres Almiray) 113405d Prepare for next development version (GitHub Actions) 348be14 Catching Error is not recommended (Sven Strickroth) Contributors We'd like to thank the following people for their contributions: Andres Almiray Melloware (@melloware) Sergio del Amo (@sdelamo) Shangeeth Rajasekar Sven Strickroth (@csware) strangelookingnerd (@strangelookingnerd)
Release 20260102.1
Changelog
- 2783897 Release version 20260102.1 (GitHub Actions)
- f40152f Update release configuration (Andres Almiray)
- c159aac fixes examples broken link (Sergio del Amo)
- dea5672 Fix #369: Ensure owasp-java-html-sanitizer targets Java 8 (Andres Almiray)
- 66b55e0 Configure release announcements (Andres Almiray)
- 113405d Prepare for next development version (GitHub Actions)
Contributors
We'd like to thank the following people for their contributions:
Release 20260101.1
Changelog
- dd3219a Release version 20260101.1 (GitHub Actions)
- 50258b9 Update release configuration (Andres Almiray)
- 4149cf0 Fix #363: CVE-2025-66021 (melloware)
- b98cdf1 Fix #363: CVE-2025-66021 (melloware)
- 17e5950 Fix resource loading in HtmlSanitizerFuzzerTest (José Pintado)
- cd23da8 Release configuration must define custom tag format (Andres Almiray)
- d978432 Update POMs with explicit URL (Andres Almiray)
- 2e32163 Add release workflow (Andres Almiray)
- 9ba6a8f Update GH workflows (Andres Almiray)
- a5c8e7b Update Maven configuration (Andres Almiray)
- df4a4a1 Update .gitignore list (Andres Almiray)
- 581ef65 Add Maven wrapper (Andres Almiray)
- d6e0463 Fix #363: CVE-2025-66021 (melloware)
- 4308989 Update SECURITY.md (Mike Samuel)
- d33151b Get rid of defunct html-types and fix copy/paste error in empiricism/pom.xml (Mike Samuel)
- fbfe3cc empiricism: remove uses of Guava (Mike Samuel)
- 6d55158 RELEASE-checklist: update with changes to module arrangement (Mike Samuel)
- dd92edf Bumped dev version (Mike Samuel)
Contributors
We'd like to thank the following people for their contributions:
- Andres Almiray (@aalmiray)
- José Pintado
- Mike Samuel (@mikesamuel)
- melloware (@melloware)
Release 20240325.1
- Remove dependency on Guava
- Raise minimum supported JVM release to 8
- HTML: Avoid duplicate link
relvalues. - HTML: Recognize foreign content syntactic context:
mathml/svg. - CSS: Better support for
font-size,overflow-wrap,word-break. - CSS: Better child combinator parsing.
- Bug: Fixed out of bounds when mixing global style attribute with others.
- Special thanks to (in lexicographic order):
Claudio Weiler, Josh England, Prakhar Maurya, Sven Strickroth, subbudvk
Release 20220608.1
Release 20220608.1
- Fix bugs in CSS tokenization
- Fix deocding of HTML character references that lack semicolons
like¶in HTML attribute values that affected
URL query parameters.
v20211018.2
Changes how we avoid problems with special tags inside <select> elements. Instead of complicating the rendering of <style> elements in all cases, now we just close special elements when they are embedded in <select> elements so no text under a <select> is interpreted as anything other than PCDATA.
This is a follow on to https://docs.google.com/document/d/11SoX296sMS0XoQiQbpxc5pNxSdbJKDJkm5BDv0zrX50/edit#heading=h.ff1sdefzjxrx and we recommend using it over v20211018.1.