⚡ Ultra-high-throughput native HTML document sanitizer and tokenization pipeline accelerated by AVX2 SIMD vector instructions, zero-copy off-heap memory addressing, and strict XSS defense profiles.
FastHTML is the high-performance document sanitation and parsing engine of the FastJava stack. It combines native C++ AVX2 vector scanning with zero-allocation memory buffers to strip malicious execution blocks (<script>, <style>, <iframe>, <object>, <embed>), scrub inline JavaScript event triggers (onclick, onload, onerror), and tokenize HTML documents in sub-microsecond latency without inflating JVM heap memory.
import fasthtml.FastHTML;
public class Demo {
public static void main(String[] args) {
// 1. Get native AVX2 accelerated FastHTML instance
FastHTML fastHtml = FastHTML.getInstance();
String dirty = "<div class=\"hero\">"
+ " <h1>Welcome <script>stealCookies()</script></h1>"
+ " <p onclick=\"malicious()\">Click <a href=\"javascript:attack()\">here</a>!</p>"
+ " <iframe src=\"http://badsite.com\"></iframe>"
+ "</div>";
// 2. Real-time native sanitization via strict whitelist
String safe = fastHtml.sanitize(dirty, FastHTML.SafetyProfile.STRICT_WHITELIST);
System.out.println(safe);
// Output: <div class="hero"><h1>Welcome </h1><p>Click <a href="#">here</a>!</p></div>
// 3. Fast zero-allocation tokenization
var tokens = fastHtml.tokenize(safe);
System.out.printf("Parsed %,d tokens in sub-microsecond latency.\n", tokens.size());
}
}- Why FastHTML?
- Key Features
- Real-World Examples
- Performance Benchmarks
- API Quick Reference
- Technical Examples & Hero Demos
- Installation
- Documentation
- License
Important
"Hardware-Vector Tag Scanning Over Heavyweight DOM Tree Allocations. Zero Heap Overhead."
Traditional Java HTML sanitizers (like Jsoup or OWASP Java HTML Sanitizer) construct comprehensive Document Object Model (DOM) trees on the JVM heap for every document. This creates heavy memory churn, garbage collection pauses, and multi-millisecond parsing latencies.
FastHTML redefines HTML security and lexing using Direct AVX2 Hardware Acceleration:
- AVX2 Vector Scanner: Employs 256-bit SIMD registers to scan for delimiters (
<,>, quotes, whitespace) simultaneously. - Zero-Copy Memory Addressing: Directly cleans HTML buffers in off-heap memory via
FastPointerandFastMemory. - No Heavyweight AST Construction: Sanitizes and tokenizes inline in a single linear pass with predictable sub-microsecond execution time.
| Feature | Jsoup (Whitelist) | OWASP Java HTML Sanitizer | FastHTML |
|---|---|---|---|
| Lexing Engine | Scalar char-by-char loop | RegEx & SAX token stream | 256-bit AVX2 SIMD vector scan |
| DOM Construction | Full DOM tree on heap | Streaming events / objects | Single-pass 0-DOM linear scan |
| Execution Latency | Milliseconds per page | Hundreds of microseconds | Sub-microsecond (< 1 µs token loop) |
| Memory Allocation | Heavy Element / Node tree | High event object churn | Zero GC (Off-heap memory buffers) |
- ⚡ Native AVX2 Acceleration: 256-bit SIMD vector instructions scanning tags, delimiters, and attributes with maximum IPC.
- 🛡️ 3 Comprehensive Safety Profiles:
STRICT_WHITELIST: Allows standard semantic elements (p,div,a,span,img,h1-h6,table, etc.) and discards untrusted tags.RELAXED: Preserves layout and custom tags while scrubbing dangerous active blocks (<script>,<style>,<iframe>, etc.).TEXT_ONLY: Strips all HTML markup, leaving only raw clean text.
- 🚫 Active XSS Neutralization: Automatically identifies and eliminates inline event handlers (
on*) and malicious URI schemes (javascript:). - 📦 Zero-Heap Native Interop: Fully integrated with
FastCore,FastPointer,FastMemory, andFastSIMD.
Secure HTML and web document preprocessing for FastAIAgent and FastAIRag prior to vector embedding:
FastHTML fastHtml = FastHTML.getInstance();
String rawWebPage = spiderResponse.bodyAsString();
// Strip all executable scripts and sanitize to safe semantic text
String sanitized = fastHtml.sanitize(rawWebPage, FastHTML.SafetyProfile.STRICT_WHITELIST);
ragPipeline.embedDocument(sanitized);Cleaning crawled pages from FastWebSpider before indexing into FastFileContentIndex:
FastWebSpider spider = FastWebSpider.open();
spider.fetchAsync("https://en.wikipedia.org/wiki/SIMD")
.thenAccept(res -> {
if (res.isSuccess()) {
String textOnly = fastHtml.sanitize(new String(res.rawBody()), FastHTML.SafetyProfile.TEXT_ONLY);
fullTextSearchIndex.insert(textOnly);
}
});Sub-microsecond XSS filtering for API endpoints and web microservices:
public String handleUserComment(String userInput) {
// Zero-overhead linear pass sanitizer
return FastHTML.getInstance().sanitize(userInput, FastHTML.SafetyProfile.RELAXED);
}Benchmarked on JDK 26 HotSpot 64-Bit (AVX2 Enabled) measuring throughput on dirty HTML streams:
| Benchmark Operation | Standard Java Sanitizers (Jsoup / OWASP) | FastHTML Native (0.1.0) | Measured Speedup | Memory Overhead |
|---|---|---|---|---|
| Document Sanitization (1 KB) | ~18.5 µs (DOM Tree Allocations) | 0.87 µs (Linear Pass) | 21.2× Faster | 0 Heap Churn |
| Active XSS Scrubbing | ~45 µs | 4.1 µs | 10.9× Faster | Zero Off-Heap Buffer |
| Memory Allocation Overhead | Full DOM Tree + Node Objects | Zero JVM Object Allocation | Eliminated GC Cycles | 0 bytes |
Run the interactive CLI demonstration: run-demo.bat
| Method / Enum | Description |
|---|---|
FastHTML.getInstance() |
Returns thread-safe native FastHTML engine instance. |
fastHtml.hasAVX2() |
Returns true if native CPU AVX2 vector extensions are active. |
fastHtml.sanitize(html, profile) |
Sanitizes HTML string using the specified safety profile. |
fastHtml.sanitize(address, len, profile) |
Zero-copy off-heap memory sanitization via native pointer. |
fastHtml.tokenize(html) |
Tokenizes HTML stream into a list of typed HTMLToken records. |
SafetyProfile.STRICT_WHITELIST |
Retains only strictly verified safe HTML tags and attributes. |
SafetyProfile.RELAXED |
Keeps custom markup, removes dangerous execution tags (<script>, etc.). |
SafetyProfile.TEXT_ONLY |
Strips all markup, returning pure plain text. |
| Case | Java Example | Launcher | Description |
|---|---|---|---|
| Interactive Terminal Diff | Demo.java | run-demo.bat |
Real-time CLI diff demonstration with colorized before/after XSS neutralization, AVX2 status, and microsecond benchmarks. |
<repositories>
<repository>
<id>jitpack.io</id>
<url>https://jitpack.io</url>
</repository>
</repositories>
<dependencies>
<dependency>
<groupId>com.github.andrestubbe</groupId>
<artifactId>FastHTML</artifactId>
<version>0.1.1</version>
</dependency>
<dependency>
<groupId>com.github.andrestubbe</groupId>
<artifactId>FastCore</artifactId>
<version>0.1.0</version>
</dependency>
<dependency>
<groupId>com.github.andrestubbe</groupId>
<artifactId>FastPointer</artifactId>
<version>0.1.1</version>
</dependency>
<dependency>
<groupId>com.github.andrestubbe</groupId>
<artifactId>FastMemory</artifactId>
<version>0.1.1</version>
</dependency>
<dependency>
<groupId>com.github.andrestubbe</groupId>
<artifactId>FastSIMD</artifactId>
<version>0.1.3</version>
</dependency>
</dependencies>repositories {
maven { url 'https://jitpack.io' }
}
dependencies {
implementation 'com.github.andrestubbe:FastHTML:0.1.1'
implementation 'com.github.andrestubbe:FastCore:0.1.0'
implementation 'com.github.andrestubbe:FastPointer:0.1.1'
implementation 'com.github.andrestubbe:FastMemory:0.1.1'
implementation 'com.github.andrestubbe:FastSIMD:0.1.3'
}Download the latest JARs directly:
- 📦 FastHTML-0.1.0.jar (The Core Library)
- ⚙️ fastcore-0.1.0.jar (Native JNI Loader)
- REFERENCE.md: Full API reference and method signatures.
- PHILOSOPHY.md: Architectural design principles and vector model.
- CHANGELOG.md: Release history and version notes.
- ROADMAP.md: Future milestones and planned features.
- COMPILE.md: Instructions for compiling from source.
MIT License. See LICENSE file for details.
Part of the FastJava Ecosystem — Making the JVM faster. Small package. Maximum speed. Zero bloat. 🚀⚡