Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41238

Опубликовано: 23 апр. 2026
Источник: redhat
CVSS3: 6.8
EPSS Низкий

Описание

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 through 3.3.3 are vulnerable to a prototype pollution-based XSS bypass. When an application uses DOMPurify.sanitize() with the default configuration (no CUSTOM_ELEMENT_HANDLING option), a prior prototype pollution gadget can inject permissive tagNameCheck and attributeNameCheck regex values into Object.prototype, causing DOMPurify to allow arbitrary custom elements with arbitrary attributes — including event handlers — through sanitization. Version 3.4.0 fixes the issue.

A flaw was found in DOMPurify, a software library used to clean potentially malicious code from web content, preventing Cross-Site Scripting (XSS) attacks. A remote attacker could exploit a vulnerability related to 'prototype pollution' to bypass DOMPurify's security checks. This allows the attacker to inject harmful code, such as event handlers, into web pages. If successfully exploited, this could lead to the execution of arbitrary code in a user's web browser.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4cryostat-openshift-console-plugin-npmFix deferred
Cryostat 4dompurifyFix deferred
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-console-plugin-rhel9Fix deferred
Migration Toolkit for Virtualizationmtv-candidate/mtv-console-plugin-rhel9Fix deferred
Multicluster Engine for Kubernetesmulticluster-engine/console-mce-rhel9Fix deferred
Node HealthCheck Operatorworkload-availability/node-healthcheck-must-gather-rhel9Fix deferred
Node HealthCheck Operatorworkload-availability/node-healthcheck-operator-bundleFix deferred
Node HealthCheck Operatorworkload-availability/node-healthcheck-rhel9-operatorFix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-console-plugin-419-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-console-plugin-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-915
https://bugzilla.redhat.com/show_bug.cgi?id=2461160DOMPurify: DOMPurify: Cross-Site Scripting bypass via prototype pollution

EPSS

Процентиль: 13%
0.00225
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.9
ubuntu
4 месяца назад

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 through 3.3.3 are vulnerable to a prototype pollution-based XSS bypass. When an application uses `DOMPurify.sanitize()` with the default configuration (no `CUSTOM_ELEMENT_HANDLING` option), a prior prototype pollution gadget can inject permissive `tagNameCheck` and `attributeNameCheck` regex values into `Object.prototype`, causing DOMPurify to allow arbitrary custom elements with arbitrary attributes — including event handlers — through sanitization. Version 3.4.0 fixes the issue.

CVSS3: 6.9
nvd
4 месяца назад

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 through 3.3.3 are vulnerable to a prototype pollution-based XSS bypass. When an application uses `DOMPurify.sanitize()` with the default configuration (no `CUSTOM_ELEMENT_HANDLING` option), a prior prototype pollution gadget can inject permissive `tagNameCheck` and `attributeNameCheck` regex values into `Object.prototype`, causing DOMPurify to allow arbitrary custom elements with arbitrary attributes — including event handlers — through sanitization. Version 3.4.0 fixes the issue.

CVSS3: 6.9
debian
4 месяца назад

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathM ...

CVSS3: 6.9
github
4 месяца назад

DOMPurify: Prototype Pollution to XSS Bypass via CUSTOM_ELEMENT_HANDLING Fallback

CVSS3: 6.9
fstec
4 месяца назад

Уязвимость функции DOMPurify.sanitize() JavaScript-библиотеки для безопасной очистки и защиты HTML-кода DOMPurify, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 13%
0.00225
Низкий

6.8 Medium

CVSS3