Nullcon Goa

The Hidden Cost Of Sanitization How Secure Parsing Can Introduce New Xss Attack Surfaces

45:42 · 28 Feb 2026 – 01 Mar 2026 · YouTube

About this talk

This talk covers the complexities of modern sanitization pipelines, which are evolving from mere content filtering to active transformation, introducing potential risks. Ashish Kataria, a security architect engineer at Synacor, discusses how issues like namespace confusion, token merging, and serialization side effects can create exploitable gaps within these pipelines. He also explains how multi-stage sanitizers and regex-based rewrites can inadvertently generate cross-site scripting (XSS) attack surfaces. The session further delves into methodologies for auditing vulnerabilities induced by sanitizers, utilizing techniques such as DOM comparison, structural mutation testing, and browser-consistent parsing models.

From event

Nullcon Goa

28 Feb 2026 – 01 Mar 2026

All event videos
Back to Watch