Medium severity6.1GHSA Advisory· Published Jul 14, 2026· Updated Jul 21, 2026
CVE-2026-49459
CVE-2026-49459
Description
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE: true }) could preserve event-handler attributes on an attacker-controlled root when a descendant name clobbered properties checked by _isClobbered, because _forceRemove no-opped on the parent-less root and _sanitizeAttributes returned early. This issue is fixed in version 3.4.6.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
dompurifynpm | < 3.4.6 | 3.4.6 |
Affected products
32- osv-coords30 versionspkg:apk/chainguard/kibana-9.4pkg:apk/chainguard/kibana-9.4-iamguardedpkg:apk/chainguard/langfuse-3-workerpkg:apk/chainguard/langfuse-fips-3-workerpkg:apk/chainguard/librechatpkg:apk/chainguard/nextcloud-server-32pkg:apk/chainguard/nextcloud-server-33pkg:apk/chainguard/nextcloud-server-34pkg:apk/chainguard/wazuh-dashboardpkg:apk/chainguard/wazuh-dashboard-alerting-dashboards-pluginpkg:apk/chainguard/wazuh-dashboard-alerting-dashboards-plugin-fipspkg:apk/chainguard/wazuh-dashboard-anomaly-detection-dashboards-pluginpkg:apk/chainguard/wazuh-dashboard-anomaly-detection-dashboards-plugin-fipspkg:apk/chainguard/wazuh-dashboard-dashboards-mapspkg:apk/chainguard/wazuh-dashboard-dashboards-maps-fipspkg:apk/chainguard/wazuh-dashboard-dashboards-notificationspkg:apk/chainguard/wazuh-dashboard-dashboards-notifications-fipspkg:apk/chainguard/wazuh-dashboard-dashboards-reportingpkg:apk/chainguard/wazuh-dashboard-dashboards-reporting-fipspkg:apk/chainguard/wazuh-dashboard-dashboards-visualizationspkg:apk/chainguard/wazuh-dashboard-dashboards-visualizations-fipspkg:apk/chainguard/wazuh-dashboard-fipspkg:apk/chainguard/wazuh-dashboard-index-management-dashboards-pluginpkg:apk/chainguard/wazuh-dashboard-index-management-dashboards-plugin-fipspkg:apk/chainguard/wazuh-dashboard-pluginspkg:apk/chainguard/wazuh-dashboard-plugins-fipspkg:apk/wolfi/langfuse-3-workerpkg:apk/wolfi/nextcloud-server-32pkg:apk/wolfi/nextcloud-server-33pkg:npm/dompurify
< 9.4.2-r6+ 29 more
- (no CPE)range: < 9.4.2-r6
- (no CPE)range: < 9.4.2-r6
- (no CPE)range: < 3.188.0-r0
- (no CPE)range: < 3.188.0-r0
- (no CPE)range: < 0.8.7-r1
- (no CPE)range: < 32.0.12-r0
- (no CPE)range: < 33.0.6-r0
- (no CPE)range: < 34.0.1-r4
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 3.188.0-r0
- (no CPE)range: < 32.0.12-r0
- (no CPE)range: < 33.0.6-r0
- (no CPE)range: < 3.4.6
Patches
Vulnerability mechanics
References
4- github.com/cure53/DOMPurify/commit/bb7739e5bccec7e1ab3dae3f3e42d02db3acaaaenvdPatch
- github.com/cure53/DOMPurify/security/advisories/GHSA-r47g-fvhr-h676nvdExploitMitigationVendor AdvisoryWEB
- github.com/advisories/GHSA-r47g-fvhr-h676ghsaADVISORY
- github.com/cure53/DOMPurify/releases/tag/3.4.6nvdRelease Notes
News mentions
0No linked articles in our index yet.