CVE-2026-65899
CVE-2026-65899 is a medium-severity vulnerability in Cure53 Dompurify with a CVSS 3.x base score of 6.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-693.
Key facts
- Severity: Medium (CVSS 3.x base score 6.1)
- CVSS v4: 5.1
- EPSS exploit prediction: 0% (33rd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-693
- Affected product: Cure53 Dompurify
- Published:
- Last modified:
Description
DOMPurify 3.0.0 before 3.4.9 does not reset the retained Trusted Types policy when clearConfig() is called, so a DOMPurify instance reused across trust boundaries stays bound to a previously supplied TRUSTED_TYPES_POLICY. A later caller that requests RETURN_TRUSTED_TYPE output receives a TrustedHTML object created by the old (potentially unsafe) policy rather than a clean default, which can lead to script execution at a Trusted Types sink. Passing TRUSTED_TYPES_POLICY: null on the later call also does not clear the retained policy.
Frequently asked questions
- What is CVE-2026-65899?
- DOMPurify 3.0.0 before 3.4.9 does not reset the retained Trusted Types policy when clearConfig() is called, so a DOMPurify instance reused across trust boundaries stays bound to a previously supplied TRUSTED_TYPES_POLICY. A later caller that requests RETURN_TRUSTED_TYPE output receives a TrustedHTML object created by the old (potentially unsafe) policy rather than a clean default, which can lead to script execution at a Trusted Types sink. Passing TRUSTED_TYPES_POLICY: null on the later call also does not clear the retained policy.
- How severe is CVE-2026-65899?
- CVE-2026-65899 has a CVSS 3.x base score of 6.1, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is low, integrity low, and availability none.
- Is CVE-2026-65899 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (33rd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-65899?
- CVE-2026-65899 affects Cure53 Dompurify. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-65899?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-65899 published?
- CVE-2026-65899 was published on 2026-07-23 and last updated on 2026-07-28.
References
- https://github.com/cure53/DOMPurify/commit/825e617753ac1169306a542d3174a77f717a0cf6
- https://github.com/cure53/DOMPurify/security/advisories/GHSA-vxr8-fq34-vvx9
- https://www.vulncheck.com/advisories/dompurify-before-trusted-types-policy-state-contamination
Affected products (1)
- cpe:2.3:a:cure53:dompurify:*:*:*:*:*:*:*:*
More vulnerabilities in Cure53 Dompurify
- CVE-2024-47875 — Critical (CVSS 10.0): DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to…
- CVE-2024-48910 — Critical (CVSS 9.1): DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to…
- CVE-2026-47423 — High (CVSS 8.2): DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed…
- CVE-2024-45801 — High (CVSS 7.3): DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It has been discovered that…
- CVE-2026-65898 — High (CVSS 7.2): DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an…
- CVE-2026-66010 — Medium (CVSS 6.1): DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via…
All CVEs affecting Cure53 Dompurify →
Other CWE-693 (Protection Mechanism Failure) vulnerabilities
- CVE-2026-93606 — Critical (CVSS 10.0): vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host…
- CVE-2026-93605 — Critical (CVSS 10.0): vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits…
- CVE-2026-92956 — Critical (CVSS 10.0): vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on…
- CVE-2026-75874 — Critical (CVSS 10.0): Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Thunderbird 154,…
- CVE-2026-47140 — Critical (CVSS 10.0): vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM blocks several dangerous Node.js builtins…
- CVE-2026-34208 — Critical (CVSS 10.0): SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, SandboxJS blocks direct assignment to global objects…
Browse all CWE-693 (Protection Mechanism Failure) vulnerabilities →