VYPR

Dompurify

by RubyGems

Source repositories

CVEs (1)

  • CVE-2026-66010MedJul 24, 2026
    risk 0.33cvss 6.1epss 0.00

    DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attributes on custom elements that later…