CVE-2026-65903

MEDIUM CVSS 4.0: 5.1 EPSS 0.19%
Updated Jul 23, 2026
DOMPurify
Parameter Value
CVSS 5.1 (MEDIUM)
Affected Versions before 3.4.0
Type CWE-697
Vendor DOMPurify
Public PoC No

DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function where short-circuit evaluation allows forbidden tags to bypass FORBID_TAGS restrictions. Attackers can craft input containing tags listed in FORBID_TAGS that are also added via ADD_TAGS function, causing them to be retained in sanitized output.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
None
No privileges needed
User Interaction
Active
User action required

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v4.0

Weakness Type (CWE)