{"api_version":"v1","generated_at":"2026-10-10T05:20:00+00:00","product":{"cve_count":10,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-rails-rails-html-sanitizer-fc290fd6ab08","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/rails-html-sanitizer","name":"rails-html-sanitizer","next_cursor":null,"observations":[{"affected":"rails-html-sanitizer: >= 1.0.3, < 1.7.1","affected_versions_present":true,"cve_id":"CVE-2026-73648","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73648","fixed":"1.7.1.","last_modified":"2026-08-13T18:35:10.270Z","patch_url":"https://github.com/rails/rails-html-sanitizer/security/advisories/GHSA-cj75-f6xr-r4g7","primary_source":"","published":"2026-08-13T18:00:21.583Z"},{"affected":">= 1.6.0, < 1.6.1","affected_versions_present":true,"cve_id":"CVE-2024-53985","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-53985","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-12-11T16:47:59.133Z","patch_url":"https://github.com/rails/rails-html-sanitizer/commit/b0220b8850d52199a15f83c472d175a4122dd7b1","primary_source":"","published":"2024-12-02T21:15:57.620Z"},{"affected":">= 1.6.0, < 1.6.1","affected_versions_present":true,"cve_id":"CVE-2024-53987","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-53987","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-12-03T14:33:22.284Z","patch_url":"https://github.com/rails/rails-html-sanitizer/commit/f02ffbb8465e73920b6de0da940f5530f855965e","primary_source":"","published":"2024-12-02T21:15:48.975Z"},{"affected":">= 1.6.0, < 1.6.1","affected_versions_present":true,"cve_id":"CVE-2024-53986","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-53986","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-12-03T14:33:51.139Z","patch_url":"https://github.com/rails/rails-html-sanitizer/commit/f02ffbb8465e73920b6de0da940f5530f855965e","primary_source":"","published":"2024-12-02T21:13:01.441Z"},{"affected":">= 1.6.0, < 1.6.1","affected_versions_present":true,"cve_id":"CVE-2024-53988","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-53988","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-12-03T14:34:23.054Z","patch_url":"https://github.com/rails/rails-html-sanitizer/commit/a0a3e8b76b696446ffc6bffcff3bc7b7c6393c72","primary_source":"","published":"2024-12-02T21:09:56.440Z"},{"affected":">= 1.6.0, < 1.6.1","affected_versions_present":true,"cve_id":"CVE-2024-53989","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-53989","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-12-03T14:35:25.922Z","patch_url":"https://github.com/rails/rails-html-sanitizer/commit/16251735e36ebdc302e2f90f2a39cad56879414f","primary_source":"","published":"2024-12-02T21:07:04.296Z"},{"affected":"< 1.4.4","affected_versions_present":true,"cve_id":"CVE-2022-23520","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-23520","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-11-03T21:46:02.126Z","patch_url":"","primary_source":"","published":"2022-12-14T17:07:31.954Z"},{"affected":"< 1.4.4","affected_versions_present":true,"cve_id":"CVE-2022-23519","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-23519","fixed":"1.4.4.","last_modified":"2025-11-03T21:46:00.596Z","patch_url":"https://github.com/rails/rails-html-sanitizer/security/advisories/GHSA-9h9g-93gc-623h","primary_source":"","published":"2022-12-14T16:50:14.949Z"},{"affected":">= 1.0.3, < 1.4.4","affected_versions_present":true,"cve_id":"CVE-2022-23518","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-23518","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-11-03T21:45:59.030Z","patch_url":"","primary_source":"","published":"2022-12-14T16:22:34.460Z"},{"affected":"< 1.4.4","affected_versions_present":true,"cve_id":"CVE-2022-23517","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-23517","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-11-03T21:45:57.498Z","patch_url":"https://github.com/rails/rails-html-sanitizer/commit/56c61c0cebd1e493e8ad7bca2a0191609a4a6979","primary_source":"","published":"2022-12-14T16:10:22.304Z"},{"affected":"<= 1.0.3","affected_versions_present":true,"cve_id":"CVE-2018-3741","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-3741","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-05T04:50:30.644Z","patch_url":"https://github.com/rails/rails-html-sanitizer/commit/f3ba1a839a35f2ba7f941c15e239a1cb379d56ae","primary_source":"","published":"2018-03-30T19:00:00.000Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"Rails"}}
