Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-65903

Опубликовано: 23 июл. 2026
Источник: redhat
CVSS3: 6.1

Описание

A flaw was found in DOMPurify. A logic error in the ADD_TAGS function allows an attacker to bypass security restrictions. By crafting specific input, an attacker can cause tags that should be removed to remain in the sanitized output. This could lead to the injection of malicious content, potentially compromising the integrity of web pages.

Отчет

This Moderate flaw in DOMPurify allows an attacker to bypass content sanitization by crafting specific input, leading to the injection of malicious content. Exploitation requires user interaction, as an attacker must trick a user into processing the specially crafted input.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4cryostat-openshift-console-plugin-npmUnder investigation
Cryostat 4dompurifyUnder investigation
Cryostat 4grafana-infinity-datasource-npmUnder investigation
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-console-plugin-rhel9Under investigation
Multicluster Engine for Kubernetesmulticluster-engine/console-mce-rhel9Under investigation
Node HealthCheck Operatorworkload-availability/node-healthcheck-must-gather-rhel9Under investigation
Node HealthCheck Operatorworkload-availability/node-healthcheck-operator-bundleUnder investigation
Node HealthCheck Operatorworkload-availability/node-healthcheck-rhel9-operatorUnder investigation
OpenShift Lightspeedopenshift-lightspeed/lightspeed-agentic-console-rhel9Under investigation
OpenShift Lightspeedopenshift-lightspeed/lightspeed-console-plugin-419-rhel9Under investigation

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2506435dompurify: DOMPurify: Security bypass allows injection of malicious content

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
9 дней назад

DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function where short-circuit evaluation allows forbidden tags to bypass FORBID_TAGS restrictions. Attackers can craft input containing tags listed in FORBID_TAGS that are also added via ADD_TAGS function, causing them to be retained in sanitized output.

CVSS3: 6.1
nvd
9 дней назад

DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function where short-circuit evaluation allows forbidden tags to bypass FORBID_TAGS restrictions. Attackers can craft input containing tags listed in FORBID_TAGS that are also added via ADD_TAGS function, causing them to be retained in sanitized output.

CVSS3: 6.1
debian
9 дней назад

DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function ...

github
4 месяца назад

DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation

6.1 Medium

CVSS3