Bug 2506429 (CVE-2026-65913) - CVE-2026-65913 dompurify: DOMPurify: Cross-Site Scripting (XSS) via prototype pollution in USE_PROFILES mode
Summary: CVE-2026-65913 dompurify: DOMPurify: Cross-Site Scripting (XSS) via prototype...
Keywords:
Status: NEW
Alias: CVE-2026-65913
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2520426 2520429 2520444 2520447 2520452 2520474 2520508 2520509 2520513 2520514 2520515 2520516 2520437 2520449 2520454 2520461 2520467 2520477 2520510 2520511 2520512 2520517 2520521 2520529
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-23 14:01 UTC by OSIDB Bzimport
Modified: 2026-08-31 18:43 UTC (History)
92 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-23 14:01:35 UTC
DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass attribute filtering by polluting Array.prototype properties. Attackers can set Array.prototype properties like onclick to true, causing DOMPurify to accept event handlers as allowlisted attributes and resulting in DOM-based XSS when sanitized markup is rendered.


Note You need to log in before you can comment on or make changes to this bug.