Bug 2506436 (CVE-2026-65898) - CVE-2026-65898 dompurify: DOMPurify: Cross-site scripting via permanent attribute allowlist pollution
Summary: CVE-2026-65898 dompurify: DOMPurify: Cross-site scripting via permanent attri...
Keywords:
Status: NEW
Alias: CVE-2026-65898
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2520553 2520562 2520564 2520565 2520568 2520569 2520552 2520554 2520555 2520556 2520566 2520567 2520570 2520571
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-23 14:01 UTC by OSIDB Bzimport
Modified: 2026-08-31 17:29 UTC (History)
92 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-23 14:01:59 UTC
DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute hook, allowing the hook to permanently mutate the shared allowlist. Attackers can register a hook that conditionally allows dangerous attributes like onerror for trusted elements, then submit untrusted content that inherits the polluted allowlist and executes event handlers as stored XSS.


Note You need to log in before you can comment on or make changes to this bug.