Uploaded March 2025 | Updated September 2026, 3 weeks ago
owasp2024globalappsecsanfra.sched.com/event/1g3X8/sanitize-client-side-why-server-side-html-sanitization-is-doomed-to-fail
When a web application needs to safely render the user’s input as HTML, e.g., to enable rich text formatting, sanitization would be the solution. Generally speaking, sanitizing user input should be done on the server side, right? Well, this is not so obvious for XSS mitigation. While sanitizing on the client side sounds counterintuitive at first, in this talk, we will explain not only why it makes sense for HTML but also why it is important to do so. This talk showcases common pitfalls of sanitizing HTML server-side and dives into multiple interesting real-world vulnerabilities.
-
Managed by the OWASP® Foundation
owasp.org
owasp2024globalappsecsanfra.sched.com/event/1g3X8/sanitize-client-side-why-server-side-html-sanitization-is-doomed-to-fail
When a web application needs to safely render the user’s input as HTML, e.g., to enable rich text formatting, sanitization would be the solution. Generally speaking, sanitizing user input should be done on the server side, right? Well, this is not so obvious for XSS mitigation. While sanitizing on the client side sounds counterintuitive at first, in this talk, we will explain not only why it makes sense for HTML but also why it is important to do so. This talk showcases common pitfalls of sanitizing HTML server-side and dives into multiple interesting real-world vulnerabilities.
-
Managed by the OWASP® Foundation
owasp.org










