HtmlSanitizer 9.2.995

HtmlSanitizer

NuGet version Build status codecov.io Sonarcloud Quality Gate

netstandard2.0 net46 net8.0

HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. It uses AngleSharp to parse, manipulate, and render HTML and CSS.

Because HtmlSanitizer is based on a robust HTML parser it can also shield you from deliberate or accidental "tag poisoning" where invalid HTML in one fragment can corrupt the whole document leading to broken layout or style.

In order to facilitate different use cases, HtmlSanitizer can be customized at several levels:

  • Configure allowed HTML tags through the property AllowedTags. All other tags will be stripped.
  • Configure allowed HTML attributes through the property AllowedAttributes. All other attributes will be stripped.
  • Configure allowed CSS property names through the property AllowedCssProperties. All other styles will be stripped.
  • Configure allowed CSS at-rules through the property AllowedAtRules. All other at-rules will be stripped.
  • Configure allowed URI schemes through the property AllowedSchemes. All other URIs will be stripped.
  • Configure HTML attributes that contain URIs (such as "src", "href" etc.) through the property UriAttributes.
  • Configure HTML attributes that contain a list of URIs (such as "srcset", "ping") through the property UriListAttributes. Every entry is checked separately.
  • Provide a base URI that will be used to resolve relative URIs against.
  • Cancelable events are raised before a tag, attribute, or style is removed.

Usage

Install the HtmlSanitizer NuGet package. Then:

using Ganss.Xss;
var sanitizer = new HtmlSanitizer();
var html = @"<script>alert('xss')</script><div onload=""alert('xss')"""
    + @"style=""background-color: rgba(0, 0, 0, 1)"">Test<img src=""test.png"""
    + @"style=""background-image: url(javascript:alert('xss')); margin: 10px""></div>";
var sanitized = sanitizer.Sanitize(html, "https://www.example.com");
var expected = @"<div style=""background-color: rgba(0, 0, 0, 1)"">"
    + @"Test<img src=""https://www.example.com/test.png"" style=""margin: 10px""></div>";
Assert.Equal(expected, sanitized);

There's an online demo, plus there's also a .NET Fiddle you can play with.

More example code and a description of possible options can be found in the Wiki.

Tags allowed by default

a, abbr, acronym, address, area, article, aside, b, bdi, big, blockquote, body, br, button, caption, center, cite, code, col, colgroup, data, datalist, dd, del, details, dfn, dir, div, dl, dt, em, fieldset, figcaption, figure, font, footer, form, h1, h2, h3, h4, h5, h6, head, header, hr, html, i, img, input, ins, kbd, keygen, label, legend, li, main, map, mark, menu, menuitem, meter, nav, ol, optgroup, option, output, p, pre, progress, q, rp, rt, ruby, s, samp, section, select, small, span, strike, strong, sub, summary, sup, table, tbody, td, textarea, tfoot, th, thead, time, tr, tt, u, ul, var, wbr

Attributes allowed by default

abbr, accept-charset, accept, accesskey, action, align, alt, autocomplete, autosave, axis, bgcolor, border, cellpadding, cellspacing, challenge, char, charoff, charset, checked, cite, clear, color, cols, colspan, compact, contenteditable, coords, datetime, dir, disabled, draggable, dropzone, enctype, for, frame, headers, height, high, href, hreflang, hspace, ismap, keytype, label, lang, list, longdesc, low, max, maxlength, media, method, min, multiple, name, nohref, noshade, novalidate, nowrap, open, optimum, pattern, placeholder, prompt, pubdate, radiogroup, readonly, rel, required, rev, reversed, rows, rowspan, rules, scope, selected, shape, size, span, spellcheck, src, start, step, style, summary, tabindex, target, title, type, usemap, valign, value, vspace, width, wrap

Note: to prevent classjacking and interference with classes where the sanitized fragment is to be integrated, the class attribute is disallowed by default. It can be added as follows:

var sanitizer = new HtmlSanitizer();
sanitizer.AllowedAttributes.Add("class");
var sanitized = sanitizer.Sanitize(html);

CSS properties allowed by default

align-content, align-items, align-self, all, animation, animation-delay, animation-direction, animation-duration, animation-fill-mode, animation-iteration-count, animation-name, animation-play-state, animation-timing-function, backface-visibility, background, background-attachment, background-blend-mode, background-clip, background-color, background-image, background-origin, background-position, background-position-x, background-position-y, background-repeat, background-repeat-x, background-repeat-y, background-size, border, border-bottom, border-bottom-color, border-bottom-left-radius, border-bottom-right-radius, border-bottom-style, border-bottom-width, border-collapse, border-color, border-image, border-image-outset, border-image-repeat, border-image-slice, border-image-source, border-image-width, border-left, border-left-color, border-left-style, border-left-width, border-radius, border-right, border-right-color, border-right-style, border-right-width, border-spacing, border-style, border-top, border-top-color, border-top-left-radius, border-top-right-radius, border-top-style, border-top-width, border-width, bottom, box-decoration-break, box-shadow, box-sizing, break-after, break-before, break-inside, caption-side, caret-color, clear, clip, color, column-count, column-fill, column-gap, column-rule, column-rule-color, column-rule-style, column-rule-width, column-span, column-width, columns, content, counter-increment, counter-reset, cursor, direction, display, empty-cells, filter, flex, flex-basis, flex-direction, flex-flow, flex-grow, flex-shrink, flex-wrap, float, font, font-family, font-feature-settings, font-kerning, font-language-override, font-size, font-size-adjust, font-stretch, font-style, font-synthesis, font-variant, font-variant-alternates, font-variant-caps, font-variant-east-asian, font-variant-ligatures, font-variant-numeric, font-variant-position, font-weight, gap, grid, grid-area, grid-auto-columns, grid-auto-flow, grid-auto-rows, grid-column, grid-column-end, grid-column-gap, grid-column-start, grid-gap, grid-row, grid-row-end, grid-row-gap, grid-row-start, grid-template, grid-template-areas, grid-template-columns, grid-template-rows, hanging-punctuation, height, hyphens, image-rendering, isolation, justify-content, left, letter-spacing, line-break, line-height, list-style, list-style-image, list-style-position, list-style-type, margin, margin-bottom, margin-left, margin-right, margin-top, mask, mask-clip, mask-composite, mask-image, mask-mode, mask-origin, mask-position, mask-repeat, mask-size, mask-type, max-height, max-width, min-height, min-width, mix-blend-mode, object-fit, object-position, opacity, order, orphans, outline, outline-color, outline-offset, outline-style, outline-width, overflow, overflow-wrap, overflow-x, overflow-y, padding, padding-bottom, padding-left, padding-right, padding-top, page-break-after, page-break-before, page-break-inside, perspective, perspective-origin, pointer-events, position, quotes, resize, right, row-gap, scroll-behavior, tab-size, table-layout, text-align, text-align-last, text-combine-upright, text-decoration, text-decoration-color, text-decoration-line, text-decoration-skip, text-decoration-style, text-indent, text-justify, text-orientation, text-overflow, text-shadow, text-transform, text-underline-position, top, transform, transform-origin, transform-style, transition, transition-delay, transition-duration, transition-property, transition-timing-function, unicode-bidi, unicode-range, user-select, vertical-align, visibility, white-space, widows, width, word-break, word-spacing, word-wrap, writing-mode, z-index

CSS at-rules allowed by default

namespace, style

style refers to style declarations within other at-rules such as @media. Disallowing @namespace while allowing other types of at-rules can lead to errors. Property declarations in @font-face and @viewport are not sanitized.

Note: the style tag is disallowed by default.

URI schemes allowed by default

http, https

Note: Protocol-relative URLs (e.g. //github.com) are allowed by default (as are other relative URLs).

to allow mailto: links:

sanitizer.AllowedSchemes.Add("mailto");

Default attributes that contain URIs

action, background, cite, codebase, data, dynsrc, formaction, href, icon, longdesc, lowsrc, manifest, poster, src, xlink:href

The value of an attribute listed in UriAttributes is checked against AllowedSchemes. An attribute that carries a URI but is not listed keeps its value as-is, so if you add such an attribute to AllowedAttributes you should add it to UriAttributes as well:

sanitizer.AllowedAttributes.Add("data-thumbnail");
sanitizer.UriAttributes.Add("data-thumbnail");

Note: attributes that merely name something in the same document rather than locating a resource - usemap, classid, profile - are deliberately not treated as URI attributes. Nothing fetches them, and resolving them against a base URI would break them: usemap="#map" has to stay a hash-name reference to match its <map>.

Default attributes that contain lists of URIs

archive, ping, srcset

These hold several URIs in one value, so each entry is checked on its own and the failing ones are dropped; the attribute itself is removed only if nothing survives. srcset is parsed as a candidate list so that descriptors are kept with the URI they belong to, and commas inside a URI do not split it.

// srcset="https://example.com/a.jpg 1x, javascript:alert(1) 2x"
// becomes srcset="https://example.com/a.jpg 1x"

Checking such an attribute through UriAttributes instead would inspect the whole value as a single URI, which only ever looks at the first entry - so use UriListAttributes for these.

The srcdoc attribute

srcdoc holds a complete HTML document rather than a URI, and a browser parses and runs it in its own browsing context. It is therefore not a URI attribute: if you allow it, its content is sanitized as HTML with the same settings as the surrounding document.

sanitizer.AllowedTags.Add("iframe");
sanitizer.AllowedAttributes.Add("srcdoc");
// <iframe srcdoc="&lt;img src=x onerror=alert(1)&gt;"></iframe>
// becomes <iframe srcdoc="&lt;img src=&quot;x&quot;&gt;"></iframe>

Nested srcdoc documents are sanitized as well, up to a fixed depth, beyond which the attribute is removed.

Thread safety

The Sanitize() and SanitizeDocument() methods are thread-safe, i.e. you can use these methods on a single shared instance from different threads provided you do not simultaneously set instance or static properties. A typical use case is that you prepare an HtmlSanitizer instance once (i.e. set desired properties such as AllowedTags etc.) from a single thread, then call Sanitize()/SanitizeDocument() from multiple threads.

Text content not necessarily preserved as-is

Please note that as the input is parsed by AngleSharp's HTML parser and then rendered back out, you cannot expect the text content to be preserved exactly as it was input, even if no elements or attributes were removed. Examples:

  • 4 < 5 becomes 4 &lt; 5
  • <SPAN>test</p> becomes <span>test<p></p></span>
  • <span title='test'>test</span> becomes <span title="test">test</span>

On the other hand, although some broken HTML is fixed by the parser, the output might still contain invalid HTML. Examples:

  • <div><li>test</li></div>
  • <ul><br><li>test</li></ul>
  • <h3><p>test</p></h3>

License

MIT License

Showing the top 20 packages that depend on HtmlSanitizer.

Packages Downloads
UmbracoCms.Web
Contains the web assemblies needed to run Umbraco Cms. This package only contains assemblies and can be used for package development. Use the UmbracoCms package to setup Umbraco in Visual Studio as an ASP.NET project.
14
UmbracoCms.Web
Contains the web assemblies needed to run Umbraco Cms. This package only contains assemblies and can be used for package development. Use the UmbracoCms package to setup Umbraco in Visual Studio as an ASP.NET project.
15
UmbracoCms.Web
Contains the web assemblies needed to run Umbraco Cms. This package only contains assemblies and can be used for package development. Use the UmbracoCms package to setup Umbraco in Visual Studio as an ASP.NET project.
16
UmbracoCms.Web
Contains the web assemblies needed to run Umbraco Cms. This package only contains assemblies and can be used for package development. Use the UmbracoCms package to setup Umbraco in Visual Studio as an ASP.NET project.
17

.NET Framework 4.6.2

.NET Framework 4.7

.NET 8.0

.NET Standard 2.0

Version Downloads Last updated
9.2.995 1 11.08.2026
9.1.982 1 11.08.2026
9.1.981 1 11.08.2026
9.1.974 1 11.08.2026
9.1.973 1 11.08.2026
9.1.968-beta 1 22.07.2026
9.1.966-beta 1 20.07.2026
9.1.949-beta 1 22.06.2026
9.1.923-beta 8 04.05.2026
9.1.893-beta 13 09.02.2026
9.1.891-beta 8 17.12.2025
9.1.887-beta 13 23.08.2025
9.1.885-beta 12 23.08.2025
9.1.882-beta 14 23.08.2025
9.1.878-beta 13 23.08.2025
9.0.967 3 22.07.2026
9.0.892 13 09.02.2026
9.0.889 9 04.12.2025
9.0.886 12 23.08.2025
9.0.884 12 23.08.2025
9.0.881 14 23.08.2025
9.0.876 13 23.08.2025
9.0.873 12 23.08.2025
8.2.871-beta 14 23.08.2025
8.1.870 12 23.08.2025
8.1.866-beta 14 23.08.2025
8.1.860-beta 12 23.08.2025
8.1.844-beta 13 23.08.2025
8.1.839-beta 13 23.08.2025
8.1.812-beta 13 23.08.2025
8.1.796-beta 12 23.08.2025
8.1.748-beta 13 23.08.2025
8.1.747-beta 13 23.08.2025
8.1.745-beta 13 23.08.2025
8.1.722-beta 14 23.08.2025
8.1.719-beta 12 23.08.2025
8.1.717-beta 12 23.08.2025
8.0.865 12 23.08.2025
8.0.843 14 23.08.2025
8.0.838 12 23.08.2025
8.0.811 12 23.08.2025
8.0.795 15 23.08.2025
8.0.746 12 23.08.2025
8.0.744 13 23.08.2025
8.0.723 13 23.08.2025
8.0.718 15 23.08.2025
8.0.692 12 23.08.2025
8.0.691-beta 13 23.08.2025
8.0.690-beta 12 23.08.2025
8.0.645 15 23.08.2025
8.0.601 12 23.08.2025
7.1.542 14 23.08.2025
7.1.512 14 23.08.2025
7.1.509 14 23.08.2025
7.1.488 14 23.08.2025
7.1.475 13 23.08.2025
7.0.473 14 23.08.2025
7.0.470-beta 12 23.08.2025
6.0.453 12 23.08.2025
6.0.441 11 23.08.2025
6.0.437 13 23.08.2025
6.0.430-beta 14 23.08.2025
6.0.423-beta 14 23.08.2025
6.0.409-beta 13 23.08.2025
5.0.404 14 23.08.2025
5.0.376 13 23.08.2025
5.0.372 13 23.08.2025