Bug 2500695 (CVE-2026-49978)
| Summary: | CVE-2026-49978 dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | aazores, abarbaro, abrianik, akhatavk, akostadi, alizardo, amasferr, amctagga, anjoseph, anpicker, aoconnor, aos-team-art-private, asdas, ataylor, bniver, cdrage, chfoley, cmah, dbruscin, dkeler, dmayorov, dpaolell, dschmidt, eaguilar, ebaron, ehugonne, ewittman, flucifre, fmariani, ggrzybek, gmalinko, gmeno, gparvin, groman, hasun, janstey, jchui, jdelft, jfula, jhe, jlanda, jlledo, jmatsuok, jowilson, jprabhak, jraez, jtolenti, jupierce, jwong, jwon, kaycoth, kbempah, kshier, ktsao, kvanderr, lchilton, lgarciaa, manissin, mbenjamin, mbiarnes, mcarlett, mhackett, nboldt, nipatil, nyancey, oaljalju, omaciel, ometelka, pantinor, parichar, pjindal, ppalepu, ppostler, prdhamdh, psrna, ptisnovs, rgodfrey, rhaigner, rhel-process-autobot, rkubis, rstepani, rushinde, sdawley, sfeifer, sghai, sidsharm, simaishi, solenoci, sostapov, stcannon, suppawar, swoodman, syedriko, tasato, tcunning, teagle, thason, tsedmik, ttakamiy, vereddy, vlaad, watson-tool-maintainers, wtam, xdharmai, yfang, yguenane |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in DOMPurify, a tool designed to sanitize HTML, MathML, and SVG to prevent cross-site scripting (XSS) attacks. When performing in-place sanitization, DOMPurify could fail to properly process content within shadow DOM elements attached to a `<template>.content`. This oversight allows an attacker to embed malicious code, such as JavaScript, which could then execute when the sanitized template is used by an application, potentially leading to unauthorized actions or information disclosure.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-07-14 21:05:50 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:57590 https://access.redhat.com/errata/RHSA-2026:57590 This issue has been addressed in the following products: Red Hat build of Apicurio Registry 3.3.1 Via RHSA-2026:59360 https://access.redhat.com/errata/RHSA-2026:59360 This issue has been addressed in the following products: Red Hat AMQ Broker 7.14.1 Via RHSA-2026:66488 https://access.redhat.com/errata/RHSA-2026:66488 This issue has been addressed in the following products: Red Hat AMQ Broker 7.13.6 Via RHSA-2026:66545 https://access.redhat.com/errata/RHSA-2026:66545 |