Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-66010

Опубликовано: 24 июл. 2026
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

A flaw was found in DOMPurify. This vulnerability allows attackers to bypass application security policies by preserving sensitive attributes on custom elements. These attributes can then be re-injected into web page content, leading to Cross-Site Scripting (XSS) attacks. An attacker could exploit this to execute malicious scripts in a user's browser, potentially leading to information disclosure or unauthorized actions.

Отчет

This Moderate-impact flaw in DOMPurify allows for Cross-Site Scripting (XSS) attacks by enabling the bypass of sanitization policies for custom elements. An attacker could exploit this by crafting malicious content that, when processed by affected Red Hat products utilizing DOMPurify in their web interfaces, could lead to the execution of arbitrary client-side scripts. This could result in information disclosure or unauthorized actions within the user's browser session.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4cryostat-openshift-console-plugin-npmUnder investigation
Cryostat 4dompurifyUnder investigation
Cryostat 4grafana-infinity-datasource-npmUnder investigation
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-console-plugin-rhel9Fix deferred
Multicluster Engine for Kubernetesmulticluster-engine/console-mce-rhel9Under investigation
Node HealthCheck Operatorworkload-availability/node-healthcheck-must-gather-rhel9Fix deferred
Node HealthCheck Operatorworkload-availability/node-healthcheck-operator-bundleFix deferred
Node HealthCheck Operatorworkload-availability/node-healthcheck-rhel9-operatorFix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-agentic-console-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-console-plugin-419-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2506731dompurify: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass

EPSS

Процентиль: 6%
0.00168
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
8 дней назад

DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attributes on custom elements that later re-inject them into innerHTML sinks, creating second-order XSS gadgets.

CVSS3: 6.1
nvd
8 дней назад

DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attributes on custom elements that later re-inject them into innerHTML sinks, creating second-order XSS gadgets.

CVSS3: 6.1
debian
8 дней назад

DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook fo ...

CVSS3: 6.1
github
8 дней назад

DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attributes on custom elements that later re-inject them into innerHTML sinks, creating second-order XSS gadgets.

EPSS

Процентиль: 6%
0.00168
Низкий

6.1 Medium

CVSS3