Unknown · Domsanitizer · CVE-2026-100370
**Name of the Vulnerable Software and Affected Versions**
DOMSanitizer versions prior to 1.0.15
**Description**
An incomplete input-validation defect exists in the `isDangerousUrl()` function, which is used to reject dangerous URL values in the `href` and `xlink:href` attributes. While the `javascript:` scheme is rejected, the `data:` scheme is only rejected if the literal substring `onload` is present. Since `data:` payloads are often Base64-encoded, malicious content such as scripts or event handlers can bypass this check, allowing active markup to persist in the attributes.
**Recommendations**
Update to version 1.0.15.