NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #2450 most downloaded on crates.io
HTML Sanitization
Last release 4 days ago
03 Oct 2026
Release timing varies
gaps range from 2 weeks to 1.3 years
Nearly every release is documented
notes for 22 of 22 stable releases
26 versions withdrawn
withdrawn after publishing
11 years old
48 releases · first in 2015
Security fix: CSS sanitization only ever worked on attributes, not stylesheets. This now panics if you try to enable the style tag while also using st…
Security fixes are not backported to 4.0 any more. Only 3.3, 4.1, and 4.2 are supported.
One column per quarter.
Security fix: CSS sanitization only ever worked on attributes, not stylesheets. This now panics if you try to enable the style tag while also using st…
url() functionfix: SVG animation and set can cause XSS, because attributeName is not checked (reported by Younghun Ko, koyokr)
animation and set can cause XSS, because attributeName is not checked (reported by Younghun Ko, koyokr)Special thanks to Ivan Ivančić (ivan0912, YesWeHack) for finding this vulnerability!
Special thanks to Ivan Ivančić (ivan0912, YesWeHack) for finding this vulnerability!
fix: unexpected namespace switches after cleanup on MathML annotation-xml can cause mXSS (reported by Ivan Ivančić)
chore: upgrade to html5ever 0.37.1
chore: always strip the contents of selectedcontent elements,
since the parser will always replace it with the actual contents anyway
fix: unexpected namespace switches after cleanup can cause mXSS (reported by zzm0902@shu.edu.cn )
chore: upgrade to html5ever 0.35
chore: switch to std's LazyLock instead of once_cell's Lazy
std's LazyLock instead of once_cell's Lazyclean_content_tags conflicts with other optionsstyle attributefix: SVG animation and set can cause XSS, because attributeName is not checked (reported by Younghun Ko, koyokr)
animation and set can cause XSS, because attributeName is not checked (reported by Younghun Ko, koyokr)Special thanks to Ivan Ivančić (ivan0912, YesWeHack) for finding this vulnerability!
Special thanks to Ivan Ivančić (ivan0912, YesWeHack) for finding this vulnerability!
fix: unexpected namespace switches after cleanup can cause mXSS (reported by zzm0902@shu.edu.cn , backport 4.1.2)
Security fixes are not backported to the 2.0 branch any more. Only the v3 and v4 branches are supported.
Display trait (and ToString) instead of an inherent to_string method (breaking change)fix: SVG animation and set can cause XSS, because attributeName is not checked (reported by Younghun Ko, koyokr)
animation and set can cause XSS, because attributeName is not checked (reported by Younghun Ko, koyokr)Special thanks to Ivan Ivančić (ivan0912, YesWeHack) for finding this vulnerability!
annotation-xml can cause mXSSSpecial thanks to Ivan Ivančić (ivan0912, YesWeHack) for finding this vulnerability!
fix: unexpected namespace switches after cleanup can cause mXSS (reported by zzm0902@shu.edu.cn , backport 4.1.2)
docs: fix incorrect XSS example
UrlRelative::RewriteWithRootchore: fix broken links in documentation
chore: update to html5ever 0.26
Builder::empty() constructorchore: use #[non_exhaustive] instead of hidden variant for UrlRelative policy
#[non_exhaustive] instead of hidden variant for UrlRelative policymatches! macrofix: incorrect FF/CR handling in clean_text
clean_textis_html documentationfix: unexpected namespace switches can allow XSS via svg/mathml parsing
fix: Crash on invalid URLs in some configurations (issue #136)
feature: Whitelist generic attribute prefix
[clean_text]: https://docs.rs/ammonia/3.0.0/ammonia/fn.clean_text.html [rust-url 2.0]: https://docs.rs/url/2.0.0/url/
clean_text function.fix: split class name attribute by all ASCII whitespace, not just SP 0x20 (backported from 3.1.3)
fix: unexpected namespace switches can allow XSS via svg/mathml parsing (backported from 3.1.2)
Fix a memory leak caused by certain node types.
* Update dependencies
Bump minimum supported Rust version to 1.30.
Add "script" and "style" to the default set of [clean content tags]
IntoIterator and Borrow, so that you can pass slices directly to them.Recognize action, formaction and ping as [URL attributes] for scheme and origin filtering
action, formaction and ping as URL attributes for scheme and origin filteringBuilder::url_filter_map which allows URLs, both relative and absolute, to be pre-filteredAdd [Builder::clean_content_tags] which allows elements to be removed entirely instead of just having the tags removed
Builder::clean_content_tags which allows elements to be removed entirely instead of just having the tags removed* Update dependencies
Breaking change: The Ammonia struct is now called Builder and uses that pattern for better forward compatibility
Ammonia struct is now called Builder and uses that pattern for better forward compatibilityBuilder::clean() method now returns a Document struct instead of a String. You can use the Document::to_string method to obtain a String.keep_cleaned_elements has changed from being an off-by-default option to the only supported behaviorallowed_classes means that the class attribute is banned from tag_attributes (it used to be required)UrlRelative::Custom, allowing you to write your own relative URL resolverUrlRelative::RewriteWithBase take a custom URL. This made the url crate a public dependency.id_prefix, which can be used to avoid element id collisions with the rest of the pageBuilder, to see what everything is currently set toNothing published for this version
Nothing published for this version
Nothing published for this version
Add allowed_classes, allowing the user to set only specific items that can go in the class attribute
allowed_classes, allowing the user to set only specific items that can go in the class attributeFix a bug in the traversal code
Resolve relative URLs with a given base (off by default, you need to specify that base URL)
rel="noreferrer noopener" to links, as a security measure<br> into <br></br>Bump html5ever to 0.18 (this updates serde from 0.9 to 1.0)
* Upgrade to html5ever 0.17
Add an option to keep elements that had attributes removed
Removed the strip option. Not a security problem, but it was wrong and looked stupid. I'm not going to reintroduce this until html5ever allows me to p
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →