You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Handle <select><selectedcontent></selectedcontent></select> without crashing when no <option> is present, replace selectedcontent fallback content during parser finalization, and avoid repeated selectedcontent subtree scans.
Preserve source order and tag text when escape-mode sanitization handles disallowed rawtext/RCDATA elements with attributed or self-closing end tags.
Make stream() use namespace-aware tokenizer context for SVG/MathML CDATA, rawtext decisions, self-closing foreign tags, and foreign end-tag stack updates.
Use the correct initial tokenizer states for HTML fragment contexts such as <title>, <textarea>, <script>, <style>, and scripting-disabled <noscript>.
Use HTML rawtext/RCDATA tokenizer states for text-like elements inside SVG/MathML HTML integration points and MathML text integration points.
Generate implied end tags before removing <form> on </form> so following controls do not remain inside still-open descendants.
Keep <form> elements inside <template> from claiming the global form pointer, including table-template form insertion.
Close open <p> elements correctly around <option>, <optgroup>, <hr>, <p>, and <div> starts in <select> parsing.
Close <template> correctly when </template> is seen while parsing inside <select>.
Keep </p> and </br> foreign-content breakouts inside MathML text integration points such as <mi> and <mtext>.
Align customizable <select> parsing with Chromium for phantom </p> handling and generic custom child elements.
Security
(Severity: Low) Strip invisible Unicode during URL sink validation even when general invisible-Unicode stripping is disabled. Previously, custom policies using strip_invisible_unicode=False could preserve scheme-obfuscated values such as javascript\u200b: in otherwise URL-validated attributes.