Bug 2506432 (CVE-2026-65901) - CVE-2026-65901 dompurify: DOMPurify: Cross-site scripting vulnerability via attacker-controlled nodeName
Summary: CVE-2026-65901 dompurify: DOMPurify: Cross-site scripting vulnerability via a...
Keywords:
Status: NEW
Alias: CVE-2026-65901
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2520406 2520419 2520423 2520438 2520458 2520463 2520409 2520415 2520428 2520433 2520442 2520445 2520456 2520460
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-23 14:01 UTC by OSIDB Bzimport
Modified: 2026-08-31 17:44 UTC (History)
92 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-23 14:01:46 UTC
DOMPurify through 3.4.6 contains a cross-site scripting vulnerability in IN_PLACE mode that trusts attacker-controlled nodeName on live non-form nodes. Attackers can supply hostile live DOM objects with real script children whose observable nodeName is clobbered to appear as allowed elements, causing scripts to execute when the sanitized tree is inserted into a live document.


Note You need to log in before you can comment on or make changes to this bug.