CVE-2026-47345: Html5 Php Outputrules Missing Namespaceattrs

Classes extending `Masterminds\HTML5\Serializer\OutputRules` but failing to override `namespaceAttrs` may serialize namespace attributes (like `xmlns:*`) directly to the output without context-aware HTML encoding. If this class is used within an HTML sanitization mechanism, this omission can lead to Cross-Site Scripting (XSS) via maliciously crafted namespac

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0PHPβ
greprules fetch cve-2026-47345-html5-php-outputrules-missing-namespaceattrs --engine opengrep

Description

Classes extending `Masterminds\HTML5\Serializer\OutputRules` but failing to override `namespaceAttrs` may serialize namespace attributes (like `xmlns:*`) directly to the output without context-aware HTML encoding. If this class is used within an HTML sanitization mechanism, this omission can lead to Cross-Site Scripting (XSS) via maliciously crafted namespac