CVE-2026-65902
Description
DOMPurify before 3.4.7 (affected versions <= 3.4.5) passes direct references to the module-level DEFAULT_ALLOWED_TAGS and DEFAULT_ALLOWED_ATTR sets to the uponSanitizeElement and uponSanitizeAttribute hooks via data.allowedTags / data.allowedAttributes when sanitize is called without an explicit cfg.ALLOWED_TAGS / cfg.ALLOWED_ATTR array. A hook that mutates these fields permanently widens the default allow-lists for the lifetime of the DOMPurify instance, so all subsequent default-config sanitize calls inherit the widened defaults and attacker payloads using the poisoned tag/attribute name survive sanitization. removeAllHooks(), clearConfig(), and passing a fresh cfg do not recover the state; only constructing a new DOMPurify instance does.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
dompurifynpm | < 3.4.7 | 3.4.7 |
Affected products
31- osv-coords29 versionspkg:apk/chainguard/wazuh-dashboard-alerting-dashboards-pluginpkg:apk/chainguard/langfuse-fips-3-workerpkg:apk/chainguard/kibana-9.4pkg:apk/chainguard/nextcloud-server-32pkg:apk/wolfi/nextcloud-server-32pkg:apk/chainguard/wazuh-dashboard-dashboards-notifications-fipspkg:apk/chainguard/nextcloud-server-34pkg:apk/chainguard/wazuh-dashboard-dashboards-maps-fipspkg:apk/chainguard/wazuh-dashboard-dashboards-notificationspkg:apk/chainguard/wazuh-dashboard-dashboards-reportingpkg:apk/chainguard/wazuh-dashboard-dashboards-visualizations-fipspkg:apk/chainguard/wazuh-dashboard-fipspkg:apk/chainguard/wazuh-dashboard-pluginspkg:apk/chainguard/wazuh-dashboard-plugins-fipspkg:apk/wolfi/langfuse-3-workerpkg:apk/chainguard/wazuh-dashboardpkg:apk/chainguard/wazuh-dashboard-dashboards-mapspkg:apk/chainguard/wazuh-dashboard-alerting-dashboards-plugin-fipspkg:apk/chainguard/wazuh-dashboard-dashboards-visualizationspkg:apk/chainguard/librechatpkg:apk/chainguard/wazuh-dashboard-anomaly-detection-dashboards-pluginpkg:apk/chainguard/wazuh-dashboard-index-management-dashboards-pluginpkg:apk/chainguard/kibana-9.4-iamguardedpkg:apk/chainguard/wazuh-dashboard-dashboards-reporting-fipspkg:apk/wolfi/nextcloud-server-33pkg:apk/chainguard/langfuse-3-workerpkg:apk/chainguard/nextcloud-server-33pkg:apk/chainguard/wazuh-dashboard-anomaly-detection-dashboards-plugin-fipspkg:apk/chainguard/wazuh-dashboard-index-management-dashboards-plugin-fips
< 4.14.5-r7+ 28 more
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 3.192.0-r0
- (no CPE)range: < 9.4.2-r6
- (no CPE)range: < 32.0.12-r0
- (no CPE)range: < 32.0.12-r0
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 34.0.1-r4
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 3.191.0-r0
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 0.8.7-r1
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 9.4.2-r6
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 33.0.6-r0
- (no CPE)range: < 3.191.0-r0
- (no CPE)range: < 33.0.6-r0
- (no CPE)range: < 4.14.5-r7
- (no CPE)range: < 4.14.5-r7
Patches
Vulnerability mechanics
References
4- github.com/cure53/DOMPurify/commit/7996f1dc78eb8b7922388aed75d94a9f8fad9a36nvdPatch
- github.com/cure53/DOMPurify/security/advisories/GHSA-76mc-f452-cxcmnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-76mc-f452-cxcmghsaADVISORY
- www.vulncheck.com/advisories/dompurify-before-hook-mutation-pollution-via-allowedtagsnvdThird Party Advisory
News mentions
0No linked articles in our index yet.