Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function where short-circuit evaluation allows forbidden tags to bypass FORBID_TAGS restrictions. Attackers can craft input containing tags listed in FORBID_TAGS that are also added via ADD_TAGS function, causing them to be retained in sanitized output.
This CVE is for a different package in a different ecosystem that happens to share a similar name
Reopening: closed in error by my triage tooling as a cross-ecosystem false positive. Re-triaging.
This CVE is in a JavaScript/NodeJS package; the JavaScript here is not shipped in the binary RPMs.