VDB

CVE-2026-65899

CVE-2026-65899 PUBLISHED CVSS 5.1 MEDIUM

Reported by VulnCheck · Published July 23, 2026

DOMPurify 3.0.0 before 3.4.9 does not reset the retained Trusted Types policy when clearConfig() is called, so a DOMPurify instance reused across trust boundaries stays bound to a previously supplied TRUSTED_TYPES_POLICY. A later caller that requests RETURN_TRUSTED_TYPE output receives a TrustedHTML object created by the old (potentially unsafe) policy rather than a clean default, which can lead to script execution at a Trusted Types sink. Passing TRUSTED_TYPES_POLICY: null on the later call also does not clear the retained policy.

Risk Scores

CVSS 4.0
5.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Affected Products

VendorProductVersions
cure53DOMPurify0, 3.4.9
wolfinextcloud-server-330, 0, 0
chainguardgitlab-rails-ce-19.10, 0
cure53dompurify0, 0, 0
wolfinextcloud-server-320, 0, 0
chainguardkibana-9.20, 0, 0
wolfilangfuse-30, 0, 0
chainguardlangfuse-fips-30, 0, 0
chainguardopensearch-dashboards-30, 0, 0
cure53DOMPurify0, 0, 3.4.9
chainguardlangfuse-30, 0, 0
chainguardnextcloud-server-330, 0, 0
chainguardwazuh-dashboard0, 0, 0
chainguardlibrechat0, 0, 0
chainguardnextcloud-server-340, 0, 0
chainguardnextcloud-server-320, 0, 0
chainguardkibana-9.40, 0, 0
chainguardwazuh-dashboard-fips0, 0, 0
chainguardgitlab-rails-ce-fips-19.10, 0
chainguardkibana-9.10, 0, 0

…and 2 more

Timeline

  • Jun 15, 2026 CVE Published
  • Jul 23, 2026 Coalition ESS Score
  • Jul 25, 2026 EPSS Score
  • Jul 26, 2026 Security Advisory
  • Aug 7, 2026 EPSS Score
  • Aug 24, 2026 EPSS Score
  • Aug 28, 2026 EPSS Score
  • Sep 5, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 16, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›