Search CVE reports


Toggle filters

381 – 390 of 41070 results

Status is adjusted based on your filters.


CVE-2026-65913

Medium priority
Needs evaluation

DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass attribute filtering by polluting Array.prototype properties. Attackers can set Array.prototype properties...

1 affected package

node-dompurify

Package 24.04 LTS
node-dompurify Needs evaluation
Show less packages

CVE-2026-65912

Medium priority
Needs evaluation

DOMPurify before 3.3.2 contains a URI validation bypass vulnerability when ADD_ATTR is provided as a predicate function via EXTRA_ELEMENT_HANDLING.attributeCheck. Attackers can supply a predicate that accepts specific attribute...

1 affected package

node-dompurify

Package 24.04 LTS
node-dompurify Needs evaluation
Show less packages

CVE-2026-65911

Medium priority
Needs evaluation

In DOMPurify through 3.3.3, function predicates supplied via ADD_ATTR or ADD_TAGS to DOMPurify.sanitize() persist in internal state (EXTRA_ELEMENT_HANDLING) across subsequent sanitize() calls on the same instance. If a later call...

1 affected package

node-dompurify

Package 24.04 LTS
node-dompurify Needs evaluation
Show less packages

CVE-2026-65904

Medium priority
Needs evaluation

DOMPurify through 3.3.3 fails to sanitize DOM elements passed via IN_PLACE mode when the element originates from a different window/realm (e.g., an iframe's contentDocument). A cross-realm instanceof check in the private _isNode()...

1 affected package

node-dompurify

Package 24.04 LTS
node-dompurify Needs evaluation
Show less packages

CVE-2026-65903

Medium priority
Needs evaluation

DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function where short-circuit evaluation allows forbidden tags to bypass FORBID_TAGS restrictions. Attackers can craft input containing tags listed in FORBID_TAGS that...

1 affected package

node-dompurify

Package 24.04 LTS
node-dompurify Needs evaluation
Show less packages

CVE-2026-65902

Medium priority
Needs evaluation

DOMPurify before 3.4.7 (affected versions <= 3.4.5) passes direct references to the module-level DEFAULT_ALLOWED_TAGS and DEFAULT_ALLOWED_ATTR sets to the uponSanitizeElement and uponSanitizeAttribute hooks via data.allowedTags /...

1 affected package

node-dompurify

Package 24.04 LTS
node-dompurify Needs evaluation
Show less packages

CVE-2026-65901

Medium priority
Needs evaluation

DOMPurify through 3.4.6 contains a cross-site scripting vulnerability in IN_PLACE mode that trusts attacker-controlled nodeName on live non-form nodes. Attackers can supply hostile live DOM objects with real script children whose...

1 affected package

node-dompurify

Package 24.04 LTS
node-dompurify Needs evaluation
Show less packages

CVE-2026-65900

Medium priority
Needs evaluation

DOMPurify versions >=3.0.0 and before 3.4.8, when configured with SAFE_FOR_TEMPLATES together with a DOM output mode (RETURN_DOM, RETURN_DOM_FRAGMENT, or IN_PLACE), fail to strip template expressions (e.g. ${evil}, {{evil}},...

1 affected package

node-dompurify

Package 24.04 LTS
node-dompurify Needs evaluation
Show less packages

CVE-2026-65899

Medium priority
Needs evaluation

DOMPurify 3.0.0 before 3.4.9 does not reset the retained Trusted Types policy when clearConfig() is called, so a DOMPurify instance reused across trust boundaries stays bound to a previously supplied TRUSTED_TYPES_POLICY. A later...

1 affected package

node-dompurify

Package 24.04 LTS
node-dompurify Needs evaluation
Show less packages

CVE-2026-65898

Medium priority
Needs evaluation

DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute hook, allowing the hook to permanently mutate the shared allowlist. Attackers can register a hook that...

1 affected package

node-dompurify

Package 24.04 LTS
node-dompurify Needs evaluation
Show less packages