PT-2026-63985 · Dompurify · Dompurify

·

CVE-2026-65899

·

Published

2026-06-15

·

Updated

2026-09-08

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions DOMPurify versions 3.0.0 through 3.4.8
Description The software fails to reset the retained Trusted Types policy when the clearConfig() function is called. Consequently, a DOMPurify instance reused across trust boundaries remains bound to a previously supplied TRUSTED TYPES POLICY. A subsequent caller requesting RETURN TRUSTED TYPE output receives a TrustedHTML object created by the previous, potentially unsafe policy instead of a clean default. This can result in script execution at a Trusted Types sink. Additionally, passing TRUSTED TYPES POLICY: null during a later call fails to clear the retained policy.
Recommendations Update DOMPurify to version 3.4.9 or later.

Exploit

Fix

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65899
GHSA-VXR8-FQ34-VVX9
OPENSUSE-SU-2026:11723-1

Affected Products

Dompurify