VDB
CVE-2026-65914
CVE-2026-65914
PUBLISHED
CVSS 5.3 MEDIUM
Reported by VulnCheck · Published July 23, 2026
DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing contexts using innerHTML with wrappers like script, xmp, iframe, noembed, noframes, or noscript. Attackers can craft payloads with closing sequences that break out of the wrapper context during reparsing, reactivating dangerous markup with event handlers to execute JavaScript.
Risk Scores
CVSS 4.0
5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cure53 | DOMPurify | 0, 3.3.2 |
| cure53 | DOMPurify | 0, 3.3.2 |
| chainguard | wazuh-dashboard | 0, 0, 0 |
| cure53 | dompurify | 0 |
Timeline
- Mar 27, 2026 CVE Published
- Jul 23, 2026 Coalition ESS Score
- Jul 25, 2026 EPSS Score
- Jul 26, 2026 Security Advisory
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score
- Sep 5, 2026 EPSS Score
References
- GitHub Security Advisory (GHSA-h8r8-wccr-v5f2) vendor-advisory
- VulnCheck Advisory: DOMPurify before 3.3.2 Mutation XSS via Re-Contextualization third-party-advisory