VDB

CVE-2026-65900

CVE-2026-65900 PUBLISHED CVSS 5.1 MEDIUM

Reported by VulnCheck · Published July 23, 2026

DOMPurify versions >=3.0.0 and before 3.4.8, when configured with SAFE_FOR_TEMPLATES together with a DOM output mode (RETURN_DOM, RETURN_DOM_FRAGMENT, or IN_PLACE), fail to strip template expressions (e.g. ${evil}, {{evil}}, <%evil%>) inside <template> element content. The final normalization/scrub pass (_scrubTemplateExpressions) uses a NodeIterator and node.normalize() that do not descend into template.content, so expressions that only form after adjacent text nodes merge survive sanitization. This bypasses SAFE_FOR_TEMPLATES and can allow a downstream template engine to evaluate attacker-supplied expressions. The string output path is not affected.

Risk Scores

CVSS 4.0
5.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Affected Products

VendorProductVersions
cure53DOMPurify3.0.0, 3.4.8
wolfinextcloud-server-330, 0, 0
chainguardlangfuse-30, 0, 0
chainguardwazuh-dashboard-fips0, 0, 0
wolfilangfuse-30, 0, 0
chainguardlangfuse-fips-30, 0, 0
chainguardkibana-9.40, 0, 0
chainguardlibrechat0, 0, 0
chainguardnextcloud-server-330, 0, 0
cure53DOMPurify3.4.8, 3.0.0
cure53dompurify3.0.0
chainguardnextcloud-server-340, 0, 0
chainguardwazuh-dashboard0, 0, 0
chainguardgitlab-rails-ce-fips-19.10, 0
wolfinextcloud-server-320, 0, 0
chainguardnextcloud-server-320, 0, 0
chainguardgitlab-rails-ce-19.10, 0

Timeline

  • Jun 15, 2026 CVE Published
  • Jul 23, 2026 Coalition ESS Score
  • Jul 25, 2026 EPSS Score
  • Jul 26, 2026 Security Advisory
  • Aug 7, 2026 EPSS Score
  • Aug 24, 2026 EPSS Score
  • Sep 5, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›