Bug 2506430 (CVE-2026-65914) - CVE-2026-65914 dompurify: DOMPurify: Cross-Site Scripting vulnerability allows arbitrary code execution
Summary: CVE-2026-65914 dompurify: DOMPurify: Cross-Site Scripting vulnerability allow...
Keywords:
Status: NEW
Alias: CVE-2026-65914
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2520395 2520397 2520401 2520403 2520405 2520435 2520494 2520496 2520497 2520498 2520499 2520503 2520396 2520399 2520407 2520411 2520421 2520424 2520495 2520500 2520501 2520502 2520505 2520506
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-23 14:01 UTC by OSIDB Bzimport
Modified: 2026-08-31 18:50 UTC (History)
92 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-23 14:01:38 UTC
DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing contexts using innerHTML with wrappers like script, xmp, iframe, noembed, noframes, or noscript. Attackers can craft payloads with closing sequences that break out of the wrapper context during reparsing, reactivating dangerous markup with event handlers to execute JavaScript.


Note You need to log in before you can comment on or make changes to this bug.