ammonia
Activity
- Latest release
- 1mo ago
- Total releases
- 45
- Cadence
- ~2 months
- Last 12 months
- 6
Details
- License
- MIT OR Apache-2.0
- First release
- Sep 04, 2015
| Version | Released | |
|---|---|---|
4.1.4
unknown
|
4.1.4
unknown
Dependencies (6)
|
|
4.0.3
unknown
|
4.0.3
unknown
Dependencies (7)
|
|
3.3.3
unknown
|
3.3.3
unknown
Dependencies (7)
|
|
4.1.3
unknown
1 CVE
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev |
4.1.3
unknown
Dependencies (6)
|
|
4.0.2
unknown
1 CVE
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev |
4.0.2
unknown
Dependencies (7)
|
|
3.3.2
unknown
1 CVE
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev |
3.3.2
unknown
Dependencies (7)
|
|
3.3.1
unknown
2 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev |
3.3.1
unknown
Dependencies (7)
|
|
4.0.1
unknown
2 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev |
4.0.1
unknown
Dependencies (7)
|
|
4.1.2
unknown
2 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev |
4.1.2
unknown
Dependencies (7)
|
|
4.1.1
unknown
3 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev |
4.1.1
unknown
Dependencies (7)
|
|
4.1.0
unknown
3 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev |
4.1.0
unknown
Dependencies (7)
|
|
4.0.0
unknown
3 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev |
4.0.0
unknown
Dependencies (7)
|
|
3.3.0
unknown
3 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev |
3.3.0
unknown
Dependencies (7)
|
|
3.2.1
unknown
3 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev |
3.2.1
unknown
Dependencies (7)
|
|
3.2.0
unknown
3 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev |
3.2.0
unknown
Dependencies (7)
|
|
3.1.4
unknown
3 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev |
3.1.4
unknown
Dependencies (8)
|
|
3.1.3
unknown
3 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev |
3.1.3
unknown
Dependencies (9)
+ 1 more |
|
2.1.4
unknown
3 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev |
2.1.4
unknown
Dependencies (8)
|
|
2.1.3
unknown
3 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev |
2.1.3
unknown
Dependencies (8)
|
|
3.1.2
unknown
yanked
4 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-p2g9-94wh-65c2
RUSTSEC-2022-0003
Jun 16, 2022
Space bug in `clean_text`
Medium
An incorrect mapping from HTML specification to ASCII codes was used. Because HTML treats the Form Feed as whitespace, code like this has an injection bug:
Applications are not affected if they quote their attributes, or if they don't use Fixed in
3.1.3
References Updated Nov 08, 2023 · Source: OSV.dev |
3.1.2
unknown
yanked
Dependencies (9)
+ 1 more |
|
3.1.1
unknown
yanked
4 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-p2g9-94wh-65c2
RUSTSEC-2022-0003
Jun 16, 2022
Space bug in `clean_text`
Medium
An incorrect mapping from HTML specification to ASCII codes was used. Because HTML treats the Form Feed as whitespace, code like this has an injection bug:
Applications are not affected if they quote their attributes, or if they don't use Fixed in
3.1.3
References Updated Nov 08, 2023 · Source: OSV.dev |
3.1.1
unknown
yanked
Dependencies (9)
+ 1 more |
|
3.1.0
unknown
yanked
4 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-p2g9-94wh-65c2
RUSTSEC-2022-0003
Jun 16, 2022
Space bug in `clean_text`
Medium
An incorrect mapping from HTML specification to ASCII codes was used. Because HTML treats the Form Feed as whitespace, code like this has an injection bug:
Applications are not affected if they quote their attributes, or if they don't use Fixed in
3.1.3
References Updated Nov 08, 2023 · Source: OSV.dev |
3.1.0
unknown
yanked
Dependencies (9)
+ 1 more |
|
3.0.0
unknown
yanked
5 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-p2g9-94wh-65c2
RUSTSEC-2022-0003
Jun 16, 2022
Space bug in `clean_text`
Medium
An incorrect mapping from HTML specification to ASCII codes was used. Because HTML treats the Form Feed as whitespace, code like this has an injection bug:
Applications are not affected if they quote their attributes, or if they don't use Fixed in
3.1.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-38193
GHSA-5325-xw5m-phm3
RUSTSEC-2021-0074
Aug 25, 2021
Cross-site Scripting in ammonia
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870. Fixed in
2.1.3
3.1.0
References Updated Nov 08, 2023 · Source: OSV.dev |
3.0.0
unknown
yanked
Dependencies (8)
|
|
2.1.2
unknown
yanked
4 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-38193
GHSA-5325-xw5m-phm3
RUSTSEC-2021-0074
Aug 25, 2021
Cross-site Scripting in ammonia
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870. Fixed in
2.1.3
3.1.0
References Updated Nov 08, 2023 · Source: OSV.dev |
2.1.2
unknown
yanked
Dependencies (8)
|
|
2.1.1
unknown
yanked
4 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-38193
GHSA-5325-xw5m-phm3
RUSTSEC-2021-0074
Aug 25, 2021
Cross-site Scripting in ammonia
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870. Fixed in
2.1.3
3.1.0
References Updated Nov 08, 2023 · Source: OSV.dev |
2.1.1
unknown
yanked
Dependencies (7)
|
|
2.1.0
unknown
yanked
4 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-38193
GHSA-5325-xw5m-phm3
RUSTSEC-2021-0074
Aug 25, 2021
Cross-site Scripting in ammonia
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870. Fixed in
2.1.3
3.1.0
References Updated Nov 08, 2023 · Source: OSV.dev |
2.1.0
unknown
yanked
Dependencies (7)
|
|
2.0.0
unknown
yanked
5 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-38193
GHSA-5325-xw5m-phm3
RUSTSEC-2021-0074
Aug 25, 2021
Cross-site Scripting in ammonia
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870. Fixed in
2.1.3
3.1.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-15542
GHSA-5hp8-35wj-m525
RUSTSEC-2019-0001
Aug 25, 2021
Uncontrolled recursion in ammonia
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in the ammonia crate before 2.1.0 for Rust. There is uncontrolled recursion during HTML DOM tree serialization. Fixed in
2.1.0
References Updated Nov 08, 2023 · Source: OSV.dev |
2.0.0
unknown
yanked
Dependencies (7)
|
|
1.2.0
unknown
yanked
5 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-38193
GHSA-5325-xw5m-phm3
RUSTSEC-2021-0074
Aug 25, 2021
Cross-site Scripting in ammonia
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870. Fixed in
2.1.3
3.1.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-15542
GHSA-5hp8-35wj-m525
RUSTSEC-2019-0001
Aug 25, 2021
Uncontrolled recursion in ammonia
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in the ammonia crate before 2.1.0 for Rust. There is uncontrolled recursion during HTML DOM tree serialization. Fixed in
2.1.0
References Updated Nov 08, 2023 · Source: OSV.dev |
1.2.0
unknown
yanked
Dependencies (7)
|
|
1.1.0
unknown
yanked
5 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-38193
GHSA-5325-xw5m-phm3
RUSTSEC-2021-0074
Aug 25, 2021
Cross-site Scripting in ammonia
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870. Fixed in
2.1.3
3.1.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-15542
GHSA-5hp8-35wj-m525
RUSTSEC-2019-0001
Aug 25, 2021
Uncontrolled recursion in ammonia
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in the ammonia crate before 2.1.0 for Rust. There is uncontrolled recursion during HTML DOM tree serialization. Fixed in
2.1.0
References Updated Nov 08, 2023 · Source: OSV.dev |
1.1.0
unknown
yanked
Dependencies (7)
|
|
1.0.1
unknown
yanked
5 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-38193
GHSA-5325-xw5m-phm3
RUSTSEC-2021-0074
Aug 25, 2021
Cross-site Scripting in ammonia
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870. Fixed in
2.1.3
3.1.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-15542
GHSA-5hp8-35wj-m525
RUSTSEC-2019-0001
Aug 25, 2021
Uncontrolled recursion in ammonia
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in the ammonia crate before 2.1.0 for Rust. There is uncontrolled recursion during HTML DOM tree serialization. Fixed in
2.1.0
References Updated Nov 08, 2023 · Source: OSV.dev |
1.0.1
unknown
yanked
Dependencies (7)
|
|
1.0.0
unknown
yanked
5 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-38193
GHSA-5325-xw5m-phm3
RUSTSEC-2021-0074
Aug 25, 2021
Cross-site Scripting in ammonia
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870. Fixed in
2.1.3
3.1.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-15542
GHSA-5hp8-35wj-m525
RUSTSEC-2019-0001
Aug 25, 2021
Uncontrolled recursion in ammonia
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in the ammonia crate before 2.1.0 for Rust. There is uncontrolled recursion during HTML DOM tree serialization. Fixed in
2.1.0
References Updated Nov 08, 2023 · Source: OSV.dev |
1.0.0
unknown
yanked
Dependencies (7)
|
|
1.0.0-rc3
unknown
yanked
5 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-38193
GHSA-5325-xw5m-phm3
RUSTSEC-2021-0074
Aug 25, 2021
Cross-site Scripting in ammonia
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870. Fixed in
2.1.3
3.1.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-15542
GHSA-5hp8-35wj-m525
RUSTSEC-2019-0001
Aug 25, 2021
Uncontrolled recursion in ammonia
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in the ammonia crate before 2.1.0 for Rust. There is uncontrolled recursion during HTML DOM tree serialization. Fixed in
2.1.0
References Updated Nov 08, 2023 · Source: OSV.dev |
1.0.0-rc3
unknown
yanked
Dependencies (7)
|
|
1.0.0-rc2
unknown
yanked
5 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-38193
GHSA-5325-xw5m-phm3
RUSTSEC-2021-0074
Aug 25, 2021
Cross-site Scripting in ammonia
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870. Fixed in
2.1.3
3.1.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-15542
GHSA-5hp8-35wj-m525
RUSTSEC-2019-0001
Aug 25, 2021
Uncontrolled recursion in ammonia
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in the ammonia crate before 2.1.0 for Rust. There is uncontrolled recursion during HTML DOM tree serialization. Fixed in
2.1.0
References Updated Nov 08, 2023 · Source: OSV.dev |
1.0.0-rc2
unknown
yanked
Dependencies (7)
|
|
1.0.0-rc1
unknown
yanked
5 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-38193
GHSA-5325-xw5m-phm3
RUSTSEC-2021-0074
Aug 25, 2021
Cross-site Scripting in ammonia
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870. Fixed in
2.1.3
3.1.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-15542
GHSA-5hp8-35wj-m525
RUSTSEC-2019-0001
Aug 25, 2021
Uncontrolled recursion in ammonia
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in the ammonia crate before 2.1.0 for Rust. There is uncontrolled recursion during HTML DOM tree serialization. Fixed in
2.1.0
References Updated Nov 08, 2023 · Source: OSV.dev |
1.0.0-rc1
unknown
yanked
Dependencies (6)
|
|
0.7.0
unknown
yanked
5 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-38193
GHSA-5325-xw5m-phm3
RUSTSEC-2021-0074
Aug 25, 2021
Cross-site Scripting in ammonia
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870. Fixed in
2.1.3
3.1.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-15542
GHSA-5hp8-35wj-m525
RUSTSEC-2019-0001
Aug 25, 2021
Uncontrolled recursion in ammonia
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in the ammonia crate before 2.1.0 for Rust. There is uncontrolled recursion during HTML DOM tree serialization. Fixed in
2.1.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.7.0
unknown
yanked
Dependencies (5)
|
|
0.6.1
unknown
yanked
5 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-38193
GHSA-5325-xw5m-phm3
RUSTSEC-2021-0074
Aug 25, 2021
Cross-site Scripting in ammonia
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870. Fixed in
2.1.3
3.1.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-15542
GHSA-5hp8-35wj-m525
RUSTSEC-2019-0001
Aug 25, 2021
Uncontrolled recursion in ammonia
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in the ammonia crate before 2.1.0 for Rust. There is uncontrolled recursion during HTML DOM tree serialization. Fixed in
2.1.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.6.1
unknown
yanked
Dependencies (5)
|
|
0.6.0
unknown
yanked
5 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-38193
GHSA-5325-xw5m-phm3
RUSTSEC-2021-0074
Aug 25, 2021
Cross-site Scripting in ammonia
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870. Fixed in
2.1.3
3.1.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-15542
GHSA-5hp8-35wj-m525
RUSTSEC-2019-0001
Aug 25, 2021
Uncontrolled recursion in ammonia
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in the ammonia crate before 2.1.0 for Rust. There is uncontrolled recursion during HTML DOM tree serialization. Fixed in
2.1.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.6.0
unknown
yanked
Dependencies (4)
|
|
0.5.0
unknown
yanked
5 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-38193
GHSA-5325-xw5m-phm3
RUSTSEC-2021-0074
Aug 25, 2021
Cross-site Scripting in ammonia
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870. Fixed in
2.1.3
3.1.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-15542
GHSA-5hp8-35wj-m525
RUSTSEC-2019-0001
Aug 25, 2021
Uncontrolled recursion in ammonia
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in the ammonia crate before 2.1.0 for Rust. There is uncontrolled recursion during HTML DOM tree serialization. Fixed in
2.1.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.5.0
unknown
yanked
Dependencies (4)
|
|
0.4.0
unknown
yanked
5 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-38193
GHSA-5325-xw5m-phm3
RUSTSEC-2021-0074
Aug 25, 2021
Cross-site Scripting in ammonia
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870. Fixed in
2.1.3
3.1.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-15542
GHSA-5hp8-35wj-m525
RUSTSEC-2019-0001
Aug 25, 2021
Uncontrolled recursion in ammonia
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in the ammonia crate before 2.1.0 for Rust. There is uncontrolled recursion during HTML DOM tree serialization. Fixed in
2.1.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.4.0
unknown
yanked
Dependencies (4)
|
|
0.3.0
unknown
yanked
5 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-38193
GHSA-5325-xw5m-phm3
RUSTSEC-2021-0074
Aug 25, 2021
Cross-site Scripting in ammonia
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870. Fixed in
2.1.3
3.1.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-15542
GHSA-5hp8-35wj-m525
RUSTSEC-2019-0001
Aug 25, 2021
Uncontrolled recursion in ammonia
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in the ammonia crate before 2.1.0 for Rust. There is uncontrolled recursion during HTML DOM tree serialization. Fixed in
2.1.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.0
unknown
yanked
Dependencies (5)
|
|
0.2.0
unknown
yanked
5 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-38193
GHSA-5325-xw5m-phm3
RUSTSEC-2021-0074
Aug 25, 2021
Cross-site Scripting in ammonia
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870. Fixed in
2.1.3
3.1.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-15542
GHSA-5hp8-35wj-m525
RUSTSEC-2019-0001
Aug 25, 2021
Uncontrolled recursion in ammonia
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in the ammonia crate before 2.1.0 for Rust. There is uncontrolled recursion during HTML DOM tree serialization. Fixed in
2.1.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.2.0
unknown
yanked
Dependencies (5)
|
|
0.1.3
unknown
yanked
5 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-38193
GHSA-5325-xw5m-phm3
RUSTSEC-2021-0074
Aug 25, 2021
Cross-site Scripting in ammonia
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870. Fixed in
2.1.3
3.1.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-15542
GHSA-5hp8-35wj-m525
RUSTSEC-2019-0001
Aug 25, 2021
Uncontrolled recursion in ammonia
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in the ammonia crate before 2.1.0 for Rust. There is uncontrolled recursion during HTML DOM tree serialization. Fixed in
2.1.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.1.3
unknown
yanked
Dependencies (5)
|
|
0.1.2
unknown
yanked
5 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-38193
GHSA-5325-xw5m-phm3
RUSTSEC-2021-0074
Aug 25, 2021
Cross-site Scripting in ammonia
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870. Fixed in
2.1.3
3.1.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-15542
GHSA-5hp8-35wj-m525
RUSTSEC-2019-0001
Aug 25, 2021
Uncontrolled recursion in ammonia
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in the ammonia crate before 2.1.0 for Rust. There is uncontrolled recursion during HTML DOM tree serialization. Fixed in
2.1.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.1.2
unknown
yanked
Dependencies (5)
|
|
0.1.1
unknown
yanked
5 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-38193
GHSA-5325-xw5m-phm3
RUSTSEC-2021-0074
Aug 25, 2021
Cross-site Scripting in ammonia
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870. Fixed in
2.1.3
3.1.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-15542
GHSA-5hp8-35wj-m525
RUSTSEC-2019-0001
Aug 25, 2021
Uncontrolled recursion in ammonia
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in the ammonia crate before 2.1.0 for Rust. There is uncontrolled recursion during HTML DOM tree serialization. Fixed in
2.1.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.1.1
unknown
yanked
Dependencies (5)
|
|
0.1.0
unknown
yanked
5 CVEs
RUSTSEC-2026-0213
GHSA-m6mh-2hw2-555x
Jul 21, 2026
XSS in ammonia via SVG `animate` and `set` animation tags The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
Ammonia did not apply attribute filters based on Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default. Discovered by: Younghun Ko (@koyokr) Fixed in
3.3.3
4.0.3
4.1.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-63430
RUSTSEC-2026-0193
GHSA-9jh8-v38h-cvhr
Jun 30, 2026
mXSS in ammonia via MathML `annotation-xml` encoding strip If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser. The This vulnerability only has an effect when the
Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Discovered by: Ivan Ivančić · Date: 2026-06-29 · Found via local differential analysis and source review of ammonia's sanitisation pipeline; no third-party systems were tested. Fixed in
3.3.2
4.0.2
4.1.3
Updated Jul 17, 2026 · Source: OSV.dev
GHSA-mm7x-qfjj-5g2c
RUSTSEC-2025-0071
Sep 22, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
Network
Low
None
None
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML. This vulnerability only has an effect when the Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default. Fixed in
3.3.1
4.0.1
4.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-38193
GHSA-5325-xw5m-phm3
RUSTSEC-2021-0074
Aug 25, 2021
Cross-site Scripting in ammonia
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870. Fixed in
2.1.3
3.1.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-15542
GHSA-5hp8-35wj-m525
RUSTSEC-2019-0001
Aug 25, 2021
Uncontrolled recursion in ammonia
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in the ammonia crate before 2.1.0 for Rust. There is uncontrolled recursion during HTML DOM tree serialization. Fixed in
2.1.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.1.0
unknown
yanked
Dependencies (5)
|