CVE-2026-68749 is an inefficient regular expression complexity vulnerability in the CSS scrubber of rrrene html_sanitize_ex. The flaw is in HtmlSanitizeEx.Scrubber.CSS.scrub/1, where the declaration-matching regular expression uses an unbounded greedy character class for the CSS property name followed by a mandatory colon. When an attacker supplies a long run of word characters or hyphens that is not followed by a colon inside CSS processed during HTML sanitization, the regex engine repeatedly backtracks and retries, resulting in quadratic-time processing. Because no effective length cap is applied to CSS passed to the scrubber, a remote unauthenticated attacker can submit crafted sanitized HTML containing a long CSS declaration and trigger excessive CPU consumption. The issue affects html_sanitize_ex versions from 0.3.1 before 1.5.3.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Small Elixir proof-of-concept repository demonstrating two denial-of-service vulnerabilities in html_sanitize_ex versions prior to 1.5.3. Repository structure is minimal: mix.exs defines a Mix project and pins html_sanitize_ex to 1.5.2, README.md explains the vulnerabilities, reproduction steps, expected timing behavior, remote attack scenario, and references, and poc.exs contains the executable PoC logic. The exploit capability is availability impact only: it does not provide code execution, persistence, or data access. Instead, it generates crafted HTML inputs that force super-linear work in the sanitizer. For CVE-2026-68749, poc.exs builds a <style> payload with a long run of 'a' characters followed by '!:' and passes it to HtmlSanitizeEx.html5/1, triggering regex backtracking in CSS scrubbing. For CVE-2026-68750, it generates a large flat sequence of repeated '<b>a</b>' sibling tags and passes it to HtmlSanitizeEx.basic_html/1, triggering quadratic traversal behavior. The script measures execution time for benign versus malicious inputs and prints ratios to demonstrate the blow-up. This is a real PoC exploit rather than a detector: it actively exercises vulnerable code paths and demonstrates resource exhaustion. It is not weaponized; payloads are hardcoded and intended for local reproduction. The README also describes the realistic remote attack form: sending crafted POST bodies to web applications, such as Phoenix apps, that sanitize user-supplied rich text. The only explicit network endpoint in the repo is an illustrative example URL, not an actual command-and-control or hardcoded target.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.