Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-65903

Опубликовано: 23 июл. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 6.1

Описание

DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function where short-circuit evaluation allows forbidden tags to bypass FORBID_TAGS restrictions. Attackers can craft input containing tags listed in FORBID_TAGS that are also added via ADD_TAGS function, causing them to be retained in sanitized output.

РелизСтатусПримечание
devel

not-affected

3.4.12+dfsg-1
esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/resolute

needs-triage

jammy

needs-triage

noble

needs-triage

resolute

needs-triage

upstream

released

3.4.1+dfsg-1

Показывать по

EPSS

Процентиль: 23%
0.00325
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
redhat
2 месяца назад

DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function where short-circuit evaluation allows forbidden tags to bypass FORBID_TAGS restrictions. Attackers can craft input containing tags listed in FORBID_TAGS that are also added via ADD_TAGS function, causing them to be retained in sanitized output.

CVSS3: 6.1
nvd
2 месяца назад

DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function where short-circuit evaluation allows forbidden tags to bypass FORBID_TAGS restrictions. Attackers can craft input containing tags listed in FORBID_TAGS that are also added via ADD_TAGS function, causing them to be retained in sanitized output.

CVSS3: 6.1
debian
2 месяца назад

DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function ...

github
5 месяцев назад

DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation

EPSS

Процентиль: 23%
0.00325
Низкий

6.1 Medium

CVSS3