NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
NuGet · #480 most downloaded on NuGet
Cleans HTML from constructs that can be used for cross-site scripting (XSS)
Last release 7 days ago
01 Oct 2026
Release timing varies
gaps range from 8 days to 6 months
Rarely documented
notes for 9 of 39 stable releases
73 versions withdrawn
withdrawn after publishing
127 years old
130 releases · first in 1900
Nothing published for this version
First beta of a major version. Please test against your usage before GA — see Breaking changes below, especially if you have a custom IHtmlSanitizer i…
First beta of a major version. Please test against your usage before GA — see Breaking changes below, especially if you have a custom IHtmlSanitizer implementation or construct HtmlSanitizerOptions yourself.
IHtmlSanitizer gained new members. Anything implementing the interface directly (not just consuming HtmlSanitizer) needs updating: StyleFormatter, EncodeComment, EncodeLiteralTextElementContent, UriListAttributes, AllowCssCustomProperties, the FilterCssRule event, both SanitizeFragment overloads, and SanitizeDocument(Stream, ...).HtmlSanitizerOptions collections are now pre-populated by default. new HtmlSanitizerOptions() now seeds every collection from HtmlSanitizerDefaults — the same defaults new HtmlSanitizer() uses — instead of starting empty (#570). If you build HtmlSanitizerOptions yourself, audit it: code that relied on the old emptiness to build a minimal allowlist (e.g. setting only AllowedTags and expecting everything else to stay locked down) now gets the full default attribute/scheme/URI-attribute set for anything it doesn't explicitly reassign. Use the new HtmlSanitizerOptions.Empty() for the old blank-slate behavior.HtmlSanitizerOptions.AllowedCssClasses renamed to AllowedClasses, matching HtmlSanitizer.AllowedClasses / IHtmlSanitizer.AllowedClasses. It's also now case-insensitive by default like every other collection on the class (it wasn't before — a latent bug).SanitizeDom(string) no longer preserves attributes on the synthetic <html>/<head>/<body> wrapper elements it creates. Fixes an attribute-injection bypass (e.g. <body onload=alert(1)>) for callers that serialize more of the returned document than dom.Body.ChildNodes.AssemblyVersion bumped to 10.0.0.0. Update any binding redirects pinned to 9.0.0.0.SanitizeFragment(html, context, ...) — sanitize a fragment as if inserted into a given element/tag context (e.g. tr, ul) instead of always parsing under <body>, so context-dependent markup like a lone <th> survives.SanitizeDocument(Stream, ...) overload.UriListAttributes — screens attributes holding a list of URLs (srcset, ping) entry-by-entry, rather than as one URL.AllowCssCustomProperties — opt in to allowing CSS custom properties (--*).StyleFormatter, EncodeComment, EncodeLiteralTextElementContent — now configurable on the sanitizer/interface.FilterCssRule event, raised per CSS rule during sanitization.HtmlSanitizerOptions.Empty() for building an allowlist from scratch.Output for some previously-passing input is now more restrictive:
cite and longdesc are now screened as URL attributes.@font-face and @import at-rule declarations are now sanitized.srcdoc content is now recursively sanitized, and URI-list attributes (srcset, ping) are screened per-entry.<style type=""> content is now sanitized (previously an empty type could skip CSS filtering).SanitizeFragment rather than silently mis-parsed under HTML rules.One column per quarter.
Fix attribute bypass in SanitizeDom(string) wrapper elements
Fix attribute bypass in SanitizeDom(string) wrapper elements
AngleSharp dependency updated from 1.7.0 to 1.7.1
Fix multiple enumeration of URLs (fixes #625 )
Fix multiple enumeration of URLs (fixes #625)
Nothing published for this version
Add FilterCssRule event (fixes #622 )
Add FilterCssRule event (fixes #622)
Update to AngleSharp 1.6.0 and AngleSharp.Css 1.0.0
Update to AngleSharp 1.6.0 and AngleSharp.Css 1.0.0
Nothing published for this version
Sanitize contents of template tag
Sanitize contents of template tag
Nothing published for this version
Target net47 (fixes #580 )
Target net47 (fixes #580)
#574
#572 #573
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →