Debian Package Tracker
Register | Log in
Subscribe

ruby-rails-html-sanitizer

HTML sanitization for Rails applications

Choose email to subscribe with

general
  • source: ruby-rails-html-sanitizer (main)
  • version: 1.7.1-1
  • maintainer: Debian Ruby Team (archive) (DMD)
  • uploaders: Balasankar C [DMD] – Georg Faerber [DMD]
  • arch: all
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.3.0-1
  • o-o-sec: 1.3.0-1+deb11u1
  • oldstable: 1.4.4-1
  • stable: 1.6.2-1
  • testing: 1.7.1-1
  • unstable: 1.7.1-1
versioned links
  • 1.3.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.3.0-1+deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.4.4-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.6.2-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.7.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • ruby-rails-html-sanitizer
action needed
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2026-73648: rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. From 1.0.3 until 1.7.1, Rails::HTML::PermitScrubber restricted SVG reference elements in SVG_ALLOW_LOCAL_HREF only when they used xlink:href, even though browsers also accept the plain href attribute. Applications with non-default allowed tags that included SVG use or feImage elements could therefore permit external references; a same-origin external SVG referenced by use could execute scripts in the sanitized document's context, while feImage could load external images for tracking. Applications using the default allowed tags are not affected. This issue is fixed in version 1.7.1.
Created: 2026-08-14 Last update: 2026-08-15 17:02
1 security issue in bullseye high

There is 1 open security issue in bullseye.

1 important issue:
  • CVE-2026-73648: rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. From 1.0.3 until 1.7.1, Rails::HTML::PermitScrubber restricted SVG reference elements in SVG_ALLOW_LOCAL_HREF only when they used xlink:href, even though browsers also accept the plain href attribute. Applications with non-default allowed tags that included SVG use or feImage elements could therefore permit external references; a same-origin external SVG referenced by use could execute scripts in the sanitized document's context, while feImage could load external images for tracking. Applications using the default allowed tags are not affected. This issue is fixed in version 1.7.1.
Created: 2026-08-14 Last update: 2026-08-15 17:02
1 security issue in bookworm high

There is 1 open security issue in bookworm.

1 important issue:
  • CVE-2026-73648: rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. From 1.0.3 until 1.7.1, Rails::HTML::PermitScrubber restricted SVG reference elements in SVG_ALLOW_LOCAL_HREF only when they used xlink:href, even though browsers also accept the plain href attribute. Applications with non-default allowed tags that included SVG use or feImage elements could therefore permit external references; a same-origin external SVG referenced by use could execute scripts in the sanitized document's context, while feImage could load external images for tracking. Applications using the default allowed tags are not affected. This issue is fixed in version 1.7.1.
Created: 2026-08-14 Last update: 2026-08-15 17:02
news
[rss feed]
  • [2026-08-10] Accepted ruby-rails-html-sanitizer 1.7.1-1 (source) into unstable (Simon Quigley)
  • [2026-07-12] ruby-rails-html-sanitizer 1.7.0-2 MIGRATED to testing (Debian testing watch)
  • [2026-07-09] Accepted ruby-rails-html-sanitizer 1.7.0-2 (source) into unstable (Simon Quigley)
  • [2026-03-03] ruby-rails-html-sanitizer 1.7.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-02-28] Accepted ruby-rails-html-sanitizer 1.7.0-1 (source) into unstable (Simon Quigley)
  • [2025-03-08] ruby-rails-html-sanitizer 1.6.2-1 MIGRATED to testing (Debian testing watch)
  • [2025-03-05] Accepted ruby-rails-html-sanitizer 1.6.2-1 (source) into unstable (Utkarsh Gupta)
  • [2025-01-14] Accepted ruby-rails-html-sanitizer 1.6.2-1~exp1 (source) into experimental (Cédric Boutillier)
  • [2024-09-28] Accepted ruby-rails-html-sanitizer 1.3.0-1+deb11u1 (source) into oldstable-security (Adrian Bunk)
  • [2023-09-13] Accepted ruby-rails-html-sanitizer 1.0.4-1+deb10u2 (source) into oldoldstable (Sylvain Beucler)
  • [2023-02-09] ruby-rails-html-sanitizer 1.4.4-1 MIGRATED to testing (Debian testing watch)
  • [2023-02-09] ruby-rails-html-sanitizer 1.4.4-1 MIGRATED to testing (Debian testing watch)
  • [2023-02-05] Accepted ruby-rails-html-sanitizer 1.4.4-1 (source) into unstable (Abhijith PA)
  • [2022-12-06] Accepted ruby-rails-html-sanitizer 1.0.4-1+deb10u1 (source) into oldstable (Utkarsh Gupta)
  • [2022-11-06] ruby-rails-html-sanitizer 1.4.3-0.1 MIGRATED to testing (Debian testing watch)
  • [2022-10-29] Accepted ruby-rails-html-sanitizer 1.4.3-0.1 (source) into unstable (Adrian Bunk)
  • [2022-01-29] ruby-rails-html-sanitizer 1.4.2-2 MIGRATED to testing (Debian testing watch)
  • [2022-01-23] Accepted ruby-rails-html-sanitizer 1.4.2-2 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2021-09-01] ruby-rails-html-sanitizer 1.4.2-1 MIGRATED to testing (Debian testing watch)
  • [2021-08-30] Accepted ruby-rails-html-sanitizer 1.4.2-1 (source) into unstable (Hideki Yamane)
  • [2021-08-16] ruby-rails-html-sanitizer 1.3.0-2 MIGRATED to testing (Debian testing watch)
  • [2021-06-12] Accepted ruby-rails-html-sanitizer 1.3.0-2 (source) into unstable (Hideki Yamane)
  • [2020-04-06] Accepted ruby-rails-html-sanitizer 1.3.0-1~bpo10+1 (source all) into buster-backports, buster-backports (Debian FTP Masters) (signed by: Praveen Arimbrathodiyil)
  • [2020-02-07] ruby-rails-html-sanitizer 1.3.0-1 MIGRATED to testing (Debian testing watch)
  • [2020-02-04] Accepted ruby-rails-html-sanitizer 1.3.0-1 (source) into unstable (Georg Faerber)
  • [2018-03-29] ruby-rails-html-sanitizer 1.0.4-1 MIGRATED to testing (Debian testing watch)
  • [2018-03-23] Accepted ruby-rails-html-sanitizer 1.0.4-1 (source) into unstable (Georg Faerber) (signed by: Cédric Boutillier)
  • [2016-03-10] ruby-rails-html-sanitizer 1.0.3-2 MIGRATED to testing (Debian testing watch)
  • [2016-03-05] Accepted ruby-rails-html-sanitizer 1.0.3-2 (source) into unstable (Christian Hofstaedtler)
  • [2016-01-29] ruby-rails-html-sanitizer 1.0.3-1 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.7.1-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing