CVE-2025-66021
HighAdvisory
Published 25 Nov 2025In the index since 8 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.6
- base score, highest
- EPSS
- 0.002
- 16th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 15
- of 17,781 indexed, latest versions
- Container images
- 12
- deployed by those charts
- Fix available
- 1 of 1
- affected package
OWASP Java HTML Sanitizer is vulnerable to XSS via noscript tag and improper style tag sanitization
Carried by container images the latest versions of 15 of 17,781 indexed charts deploy, on 12 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| owasp-java-html-sanitizermaven | 20240325.1 | 20260101.1 | 12 |
- OSV records
- GHSA-g9gq-3pfx-2gw2
Charts affected
15 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| unifiunifiVerified publisher | 1.16.0 | 1 of 1See more | 7,268 |
| arlas-aiasarlas-stackVerified publisher | 28.8.0 | 1 of 22See more | 40,238 |
| bluerange-serverbluerangeOfficialVerified publisher | 1.3.1 | 1 of 1See more | 1,816 |
| damap-chartdamapVerified publisher | 0.3.0 | 1 of 5See more | 13,936 |
| unifiegebackVerified publisher | 2.1.6 | 1 of 1See more | 7,268 |
| grayloggraylogVerified publisher | 1.0.2 | 1 of 4See more | 5,261 |
| opencloudjacobcolvinVerified publisher | 0.2.3 | 1 of 13See more | 45,239 |
| unifik8sonlabVerified publisher | 0.3.7 | 1 of 1See more | 7,268 |
| my-bloody-jenkinsodavid | 0.1.218 | 1 of 1See more | 5,826 |
| keycloakpascaliskeVerified publisher | 0.2.0 | 1 of 1See more | 2,097 |
| unifiqaoruVerified publisher | 1.1.2 | 1 of 2See more | 3,642 |
| keycloaksb-helm-charts | 0.3.0 | 1 of 2See more | 2,590 |
| keycloaksikalabs | 0.1.0 | 1 of 1See more | 1,690 |
| wonder-mesh-netstrrl-helm | 2026.629.0 | 1 of 3See more | 5,063 |
| opencloudunxwaresVerified publisher | 0.2.3 | 1 of 13See more | 45,239 |
Container images carrying it
12 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| jacobalberty/ | 896c0ab82d33 | owasp-java-html-sanitizer | 20260101.1 | 3 |
| quay.io/ | 044a457e0498 | owasp-java-html-sanitizer | 20260101.1 | 2 |
| bitnamilegacy/ | da3df0976a9f | owasp-java-html-sanitizer | 20260101.1 | 1 |
| bluerange/ | 07c8f73b55df | owasp-java-html-sanitizer | 20260101.1 | 1 |
| graylog/ | 19de1aff48c2 | owasp-java-html-sanitizer | 20260101.1 | 1 |
| linuxserver/ | b6ce6968ee45 | owasp-java-html-sanitizer | 20260101.1 | 1 |
| odavid/ | e7ab3bbc948e | owasp-java-html-sanitizer | 20260101.1 | 1 |
| quay.io/ | 09a381c715ab | owasp-java-html-sanitizer | 20260101.1 | 1 |
| quay.io/ | 4388e2379b7e | owasp-java-html-sanitizer | 20260101.1 | 1 |
| quay.io/ | 6a7217a100bd | owasp-java-html-sanitizer | 20260101.1 | 1 |
| quay.io/ | 9409c59bdfb6 | owasp-java-html-sanitizer | 20260101.1 | 1 |
| quay.io/ | a93d22e13b86 | owasp-java-html-sanitizer | 20260101.1 | 1 |