Security Advisories (1)
CVE-2023-24038 (2023-01-21)

The HTML-StripScripts module through 1.06 for Perl allows _hss_attval_style ReDoS because of catastrophic backtracking for HTML content with certain style attributes.

Changes for version 1.06

  • Fixed a bug in the mailto regex RT 87872 (thanks to ANDK and SysPete) Fixed an unclosed { in the _hss_attval_size regex RT 98110, RT 104221, RT 107247, (thanks to fraserbn, jplesnik, dtenney, and SysPete) Fixed a spelling mistake (thanks to gregoa and SysPete)

Modules

Strip scripting constructs out of HTML