VDB

CVE-2026-65898

CVE-2026-65898 PUBLISHED CVSS 5.1 MEDIUM

Reported by VulnCheck · Published July 23, 2026

DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute hook, allowing the hook to permanently mutate the shared allowlist. Attackers can register a hook that conditionally allows dangerous attributes like onerror for trusted elements, then submit untrusted content that inherits the polluted allowlist and executes event handlers as stored XSS.

Risk Scores

CVSS 4.0
5.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Affected Products

VendorProductVersions
cure53DOMPurify0, 3.4.11
chainguardgitlab-rails-ce-fips-19.10, 0
chainguardlangfuse-fips-30, 0, 0
wolfinextcloud-server-330, 0, 0
chainguardlangfuse-30, 0, 0
chainguardopensearch-dashboards-20, 0, 0
chainguardlibrechat0, 0, 0
chainguardlangfuse-20, 0, 0
wolfinextcloud-server-320, 0, 0
chainguardwazuh-dashboard0, 0, 0
chainguardnextcloud-server-340, 0, 0
wolfilangfuse-30, 0, 0
chainguardopensearch-dashboards-3-fips0, 0, 0
chainguardkibana-9.40, 0, 0
cure53dompurify0
chainguardgitlab-rails-ce-19.10, 0
chainguardnextcloud-server-320, 0, 0
chainguardnextcloud-server-330, 0, 0
chainguardwazuh-dashboard-fips0, 0, 0
cure53DOMPurify0, 3.4.11

…and 1 more

Timeline

  • Jun 18, 2026 CVE Published
  • Jul 23, 2026 Coalition ESS Score
  • Jul 25, 2026 EPSS Score
  • Jul 26, 2026 Security Advisory
  • Aug 7, 2026 EPSS Score
  • Aug 24, 2026 EPSS Score
  • Sep 5, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 17, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›