The Ammonia Project maintains a focused HTML-sanitization library designed to prevent cross-site scripting attacks in web content, a narrow but structurally important component in applications that must safely render user-supplied markup. Its disclosures center on the inherent tension between sanitization completeness and parser robustness, reflected in recurring weakness classes of improper input neutralization during page generation and uncontrolled recursion. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ammonia Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-15542HIGH An issue was discovered in the ammonia crate before 2.1.0 for Rust. There is uncontrolled recursion during HTML DOM tree serialization. | Aug 26, 2019 | 7.5 | 23 | NO | NO |
CVE-2021-38193MEDIUM An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2 | Aug 8, 2021 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ammonia Project.
Media articles that mention a CVE ID that affects a product developed by Ammonia Project — matched by CVE ID, not by vendor name.