Medium severity6.1NVD Advisory· Published Jul 23, 2026· Updated Jul 28, 2026
CVE-2026-65903
CVE-2026-65903
Description
DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function where short-circuit evaluation allows forbidden tags to bypass FORBID_TAGS restrictions. Attackers can craft input containing tags listed in FORBID_TAGS that are also added via ADD_TAGS function, causing them to be retained in sanitized output.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
dompurifynpm | < 3.4.0 | 3.4.0 |
Affected products
28- osv-coords26 versionspkg:apk/chainguard/kibana-9.2pkg:apk/chainguard/langfuse-2pkg:apk/chainguard/langfuse-2-workerpkg:apk/chainguard/langfuse-3pkg:apk/chainguard/langfuse-3-workerpkg:apk/chainguard/langfuse-fips-2pkg:apk/chainguard/langfuse-fips-2-workerpkg:apk/chainguard/langfuse-fips-3pkg:apk/chainguard/langfuse-fips-3-workerpkg:apk/chainguard/librechatpkg:apk/chainguard/nextcloud-server-33pkg:apk/chainguard/opensearch-dashboards-3pkg:apk/chainguard/opensearch-dashboards-3-fipspkg:apk/chainguard/wazuh-dashboard-alerting-dashboards-pluginpkg:apk/chainguard/wazuh-dashboard-anomaly-detection-dashboards-pluginpkg:apk/chainguard/wazuh-dashboard-dashboards-mapspkg:apk/chainguard/wazuh-dashboard-dashboards-notificationspkg:apk/chainguard/wazuh-dashboard-dashboards-reportingpkg:apk/chainguard/wazuh-dashboard-dashboards-visualizationspkg:apk/chainguard/wazuh-dashboard-index-management-dashboards-pluginpkg:apk/chainguard/wazuh-dashboard-pluginspkg:apk/chainguard/wazuh-dashboard-plugins-fipspkg:apk/wolfi/langfuse-3pkg:apk/wolfi/langfuse-3-workerpkg:apk/wolfi/nextcloud-server-33pkg:apk/wolfi/opensearch-dashboards-3
< 9.2.7-r5+ 25 more
- (no CPE)range: < 9.2.7-r5
- (no CPE)range: < 2.95.12-r19
- (no CPE)range: < 2.95.12-r19
- (no CPE)range: < 3.164.0-r6
- (no CPE)range: < 3.164.0-r6
- (no CPE)range: < 2.95.12-r22
- (no CPE)range: < 2.95.12-r22
- (no CPE)range: < 3.164.0-r6
- (no CPE)range: < 3.164.0-r6
- (no CPE)range: < 0.8.4-r5
- (no CPE)range: < 33.0.6-r0
- (no CPE)range: < 3.6.0-r3
- (no CPE)range: < 3.6.0-r4
- (no CPE)range: < 4.14.4-r3
- (no CPE)range: < 4.14.4-r3
- (no CPE)range: < 4.14.4-r3
- (no CPE)range: < 4.14.4-r3
- (no CPE)range: < 4.14.4-r3
- (no CPE)range: < 4.14.4-r3
- (no CPE)range: < 4.14.4-r3
- (no CPE)range: < 4.14.4-r3
- (no CPE)range: < 4.14.4-r2
- (no CPE)range: < 3.164.0-r6
- (no CPE)range: < 3.164.0-r6
- (no CPE)range: < 33.0.6-r0
- (no CPE)range: < 3.6.0-r3
Patches
Vulnerability mechanics
References
3- github.com/cure53/DOMPurify/security/advisories/GHSA-39q2-94rc-95cpnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-39q2-94rc-95cpghsaADVISORY
- www.vulncheck.com/advisories/dompurify-before-add-tags-function-bypasses-forbid-tagsnvdThird Party Advisory
News mentions
0No linked articles in our index yet.