Answer in brief
CVE-2026-9769 records a High severity (CVSS 7.5) vulnerability in justhtml before 1.10.0 Denial of Service via deeply nested HTML. The current sources do not mark it as known exploited. The current feed maps EmilStenstrom/justhtml (generic), justhtml (pip), justhtml (pypi). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps EmilStenstrom/justhtml (generic), justhtml (pip), justhtml (pypi). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| EmilStenstrom/justhtmlgeneric | >=0 <1.10.0 | 1.10.0 |
| justhtmlpip | <=1.9.1 | 1.10.0 |
| justhtmlpypi | >=0 <1.10.0 | 1.10.0 |
Published upstream
Aug 23, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 26, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 7, 2026
justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() construction, TreeBuilder.finish() unconditionally calls _populate_selectedcontent(), which recursively traverses the DOM tree via _find_elements()/_find_element() without a depth bound. An attacker who can supply HTML for parsing can provide deeply nested elements (e.g., ~1000 nested <div> tags, roughly 11 KB) to exceed CPython's default recursion limit and trigger an unhandled RecursionError, which may abort parsing, fail requests, or terminate a worker/process depending on the host application's exception handling.
Quoted source text, attributed separately from HOL analysis.