CVE-2026-68750 is an inefficient algorithmic complexity vulnerability in the traversal engine of the Elixir package html_sanitize_ex. The flaw is in HtmlSanitizeEx.Traverser.traverse/2, where the list-processing clause recurses over the tail of a sibling list and then applies flattening to an already flattened result. As a result, each sibling causes the remaining tail to be copied and re-walked, producing quadratic time behavior as sibling count increases. Because the traverser is used by every public entry point, the issue is reachable regardless of scrubber selection or special configuration. An attacker can trigger the flaw by submitting sanitized HTML containing a large flat sequence of allowed sibling elements, causing excessive resource consumption during sanitization. Affected versions are 0.3.1 through versions before 1.5.3.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Small Elixir proof-of-concept repository demonstrating two denial-of-service vulnerabilities in html_sanitize_ex versions prior to 1.5.3. Repository structure is minimal: mix.exs defines a Mix project and pins html_sanitize_ex to 1.5.2, README.md explains the vulnerabilities, reproduction steps, expected timing behavior, remote attack scenario, and references, and poc.exs contains the executable PoC logic. The exploit capability is availability impact only: it does not provide code execution, persistence, or data access. Instead, it generates crafted HTML inputs that force super-linear work in the sanitizer. For CVE-2026-68749, poc.exs builds a <style> payload with a long run of 'a' characters followed by '!:' and passes it to HtmlSanitizeEx.html5/1, triggering regex backtracking in CSS scrubbing. For CVE-2026-68750, it generates a large flat sequence of repeated '<b>a</b>' sibling tags and passes it to HtmlSanitizeEx.basic_html/1, triggering quadratic traversal behavior. The script measures execution time for benign versus malicious inputs and prints ratios to demonstrate the blow-up. This is a real PoC exploit rather than a detector: it actively exercises vulnerable code paths and demonstrates resource exhaustion. It is not weaponized; payloads are hardcoded and intended for local reproduction. The README also describes the realistic remote attack form: sending crafted POST bodies to web applications, such as Phoenix apps, that sanitize user-supplied rich text. The only explicit network endpoint in the repo is an illustrative example URL, not an actual command-and-control or hardcoded target.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.