VDB
CVE-2026-65898
CVE-2026-65898
PUBLISHED
CVSS 5.1 MEDIUM
Reported by VulnCheck · Published July 23, 2026
DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute hook, allowing the hook to permanently mutate the shared allowlist. Attackers can register a hook that conditionally allows dangerous attributes like onerror for trusted elements, then submit untrusted content that inherits the polluted allowlist and executes event handlers as stored XSS.
Risk Scores
CVSS 4.0
5.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cure53 | DOMPurify | 0, 3.4.11 |
| chainguard | gitlab-rails-ce-fips-19.1 | 0, 0 |
| chainguard | langfuse-fips-3 | 0, 0, 0 |
| wolfi | nextcloud-server-33 | 0, 0, 0 |
| chainguard | langfuse-3 | 0, 0, 0 |
| chainguard | opensearch-dashboards-2 | 0, 0, 0 |
| chainguard | librechat | 0, 0, 0 |
| chainguard | langfuse-2 | 0, 0, 0 |
| wolfi | nextcloud-server-32 | 0, 0, 0 |
| chainguard | wazuh-dashboard | 0, 0, 0 |
| chainguard | nextcloud-server-34 | 0, 0, 0 |
| wolfi | langfuse-3 | 0, 0, 0 |
| chainguard | opensearch-dashboards-3-fips | 0, 0, 0 |
| chainguard | kibana-9.4 | 0, 0, 0 |
| cure53 | dompurify | 0 |
| chainguard | gitlab-rails-ce-19.1 | 0, 0 |
| chainguard | nextcloud-server-32 | 0, 0, 0 |
| chainguard | nextcloud-server-33 | 0, 0, 0 |
| chainguard | wazuh-dashboard-fips | 0, 0, 0 |
| cure53 | DOMPurify | 0, 3.4.11 |
…and 1 more
Timeline
- Jun 18, 2026 CVE Published
- Jul 23, 2026 Coalition ESS Score
- Jul 25, 2026 EPSS Score
- Jul 26, 2026 Security Advisory
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score
- Sep 5, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 17, 2026 EPSS Score
- Sep 18, 2026 EPSS Score
References
- GitHub Security Advisory (GHSA-cmwh-pvxp-8882) vendor-advisory
- VulnCheck Advisory: DOMPurify before 3.4.11 Permanent Attribute Allowlist Pollution via setConfig third-party-advisory