Sanitize Client-Side: Why Server-Side HTML Sanitization is Doomed to Fail - Yaniv Nizry @OWASPGLOBAL
Sanitize Client-Side: Why Server-Side HTML Sanitization is Doomed to Fail - Yaniv Nizry  @OWASPGLOBAL
Uploaded March 2025 | Updated September 2026, 3 weeks ago
owasp2024globalappsecsanfra.sched.com/event/1g3X8/sanitize-client-side-why-server-side-html-sanitization-is-doomed-to-fail

When a web application needs to safely render the user’s input as HTML, e.g., to enable rich text formatting, sanitization would be the solution. Generally speaking, sanitizing user input should be done on the server side, right? Well, this is not so obvious for XSS mitigation. While sanitizing on the client side sounds counterintuitive at first, in this talk, we will explain not only why it makes sense for HTML but also why it is important to do so. This talk showcases common pitfalls of sanitizing HTML server-side and dives into multiple interesting real-world vulnerabilities.

-

Managed by the OWASP® Foundation
owasp.org
Sanitize Client-Side: Why Server-Side HTML Sanitization is Doomed to Fail - Yaniv NizryPay the Maintainers: xz utils Hack Highlights the Dangers of OSS Maintainer Burnout - Matthew ArnowHow to Embed Privacy Threat Modeling in Agile Sprint Rituals Without Slowing Teams DownOWASP Global Board of Directors Meeting - August 20259125 Days of OWASP  Did We Make Software Safer?OWASP Global Board of Directors - April 2026Global AppSec USA 2025 Washington, D.C.2022 Global AppSec San Francisco: Swathi Joshi KeynoteIndirect Prompt Injection: Architectural Testing Approaches for Real World AI/ML SystemsUnlocking Secure Development: A Deep Dive into OWASP ASVSNavigating the complex and rapidly evolving world of product and application security regulationsModernizing the Application Penetration Engagement and Reporting Lifecycle - Ryan Armstrong
OWASP Foundation |

Sanitize Client-Side: Why Server-Side HTML Sanitization is Doomed to Fail - Yaniv Nizry

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER