CVE-2024-45801
published 2024-09-16CVE-2024-45801: DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It has been discovered that malicious HTML using special nesting…
PriorityP426medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.84%
54.2th percentile
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It has been discovered that malicious HTML using special nesting techniques can bypass the depth checking added to DOMPurify in recent releases. It was also possible to use Prototype Pollution to weaken the depth check. This renders dompurify unable to avoid cross site scripting (XSS) attacks. This issue has been addressed in versions 2.5.4 and 3.1.3 of DOMPurify. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atlassian | jira_service_management | — | — |
| cure53 | dompurify | < 2.5.4 | 2.5.4 |
| cure53 | dompurify | — | — |
| cure53 | dompurify | >= 0 < 2.5.0 | 2.5.0 |
| cure53 | dompurify | >= 0 < 2.5.4 | 2.5.4 |
| cure53 | dompurify | >= 3.0.0 < 3.1.3 | 3.1.3 |
| cure53 | dompurify | >= 3.0.0 < 3.1.3 | 3.1.3 |
| cure53 | dompurify | >= 3.0.1 < 3.4.0 | 3.4.0 |
| debian | node-dompurify | < node-dompurify 2.4.1+dfsg+~2.4.0-2+deb12u1 (bookworm) | node-dompurify 2.4.1+dfsg+~2.4.0-2+deb12u1 (bookworm) |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
ghsa6.1MEDIUM
osv6.1MEDIUM
vendor_debian7.3HIGH
vendor_oracle7.3HIGH
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Utilities Applications Risk Matrix: General (DOMPurify) — CVE-2024-45801
vendor_oracle·2025-01-15·CVSS 7.3
CVE-2024-45801 [HIGH] Oracle Oracle Utilities Applications Risk Matrix: General (DOMPurify) — CVE-2024-45801
Oracle Oracle Utilities Applications Risk Matrix: General (DOMPurify) vulnerability
CVE: CVE-2024-45801
CVSS: 7.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2025 (JAN 2025)
Atlassian
CVE-2024-45801: 10.0.0 to 10.0.1 5.17.0 to 5.17.3 5.16.0 to 5.16.1 5.15.2 5.14.0 to 5.14.1 5.13.0 to 5.13.1 5.12.0 to 5.12.14 (LTS) 5.11
vendor_atlassian·2024-11-19·CVSS 10.0
CVE-2024-45801 [HIGH] CVE-2024-45801: 10.0.0 to 10.0.1 5.17.0 to 5.17.3 5.16.0 to 5.16.1 5.15.2 5.14.0 to 5.14.1 5.13.0 to 5.13.1 5.12.0 to 5.12.14 (LTS) 5.11
CVE-2024-45801: 10.0.0 to 10.0.1 5.17.0 to 5.17.3 5.16.0 to 5.16.1 5.15.2 5.14.0 to 5.14.1 5.13.0 to 5.13.1 5.12.0 to 5.12.14 (LTS) 5.11
10.0.0 to 10.0.1 5.17.0 to 5.17.3 5.16.0 to 5.16.1 5.15.2 5.14.0 to 5.14.1 5.13.0 to 5.13.1 5.12.0 to 5.12.14 (LTS) 5.11.0 to 5.11.3 5.10.0 to 5.10.2 5.9.0 to 5.9.2 5.8.0 to 5.8.2 5.7.0 to 5.7.2 5.6.0 5.5.0 to 5.5.1 5.4.1 to 5.4.27 (LTS) 5.3.2 to 5.3.3 5.2.1
CVE: CVE-2024-45801
Affected products: Jira Service Management
Oracle
Oracle Oracle Application Express Risk Matrix: General (DOMPurify) — CVE-2024-45801
vendor_oracle·2024-10-15·CVSS 6.3
CVE-2024-45801 [HIGH] Oracle Oracle Application Express Risk Matrix: General (DOMPurify) — CVE-2024-45801
Oracle Oracle Application Express Risk Matrix: General (DOMPurify) vulnerability
CVE: CVE-2024-45801
CVSS: 6.3
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuoct2024 (OCT 2024)
Red Hat
dompurify: XSS vulnerability via prototype pollution
vendor_redhat·2024-09-16·CVSS 7.3
CVE-2024-45801 [HIGH] CWE-1333 dompurify: XSS vulnerability via prototype pollution
dompurify: XSS vulnerability via prototype pollution
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It has been discovered that malicious HTML using special nesting techniques can bypass the depth checking added to DOMPurify in recent releases. It was also possible to use Prototype Pollution to weaken the depth check. This renders dompurify unable to avoid cross site scripting (XSS) attacks. This issue has been addressed in versions 2.5.4 and 3.1.3 of DOMPurify. All users are advised to upgrade. There are no known workarounds for this vulnerability.
A flaw was found in DOMPurify. This issue may allow an attacker to use specially-crafted HTML to bypass the depth checking or use Prototype Pollution to weaken the depth check, which can lead to cro
Debian
CVE-2024-45801: node-dompurify - DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathM...
vendor_debian·2024·CVSS 7.3
CVE-2024-45801 [HIGH] CVE-2024-45801: node-dompurify - DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathM...
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It has been discovered that malicious HTML using special nesting techniques can bypass the depth checking added to DOMPurify in recent releases. It was also possible to use Prototype Pollution to weaken the depth check. This renders dompurify unable to avoid cross site scripting (XSS) attacks. This issue has been addressed in versions 2.5.4 and 3.1.3 of DOMPurify. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Scope: local
bookworm: resolved (fixed in 2.4.1+dfsg+~2.4.0-2+deb12u1)
forky: resolved
sid: resolved
trixie: resolved
GHSA
DOMPurify: Prototype Pollution to XSS Bypass via CUSTOM_ELEMENT_HANDLING Fallback
ghsa·2026-04-22·CVSS 6.1
CVE-2026-41238 [MEDIUM] CWE-1321 DOMPurify: Prototype Pollution to XSS Bypass via CUSTOM_ELEMENT_HANDLING Fallback
DOMPurify: Prototype Pollution to XSS Bypass via CUSTOM_ELEMENT_HANDLING Fallback
## Summary
DOMPurify versions 3.0.1 through 3.3.3 (latest) are vulnerable to a prototype pollution-based XSS bypass. When an application uses `DOMPurify.sanitize()` with the default configuration (no `CUSTOM_ELEMENT_HANDLING` option), a prior prototype pollution gadget can inject permissive `tagNameCheck` and `attributeNameCheck` regex values into `Object.prototype`, causing DOMPurify to allow arbitrary custom elements with arbitrary attributes — including event handlers — through sanitization.
## Affected Versions
- **3.0.1 through 3.3.3** (current latest) — all affected
- **3.0.0 and all 2.x versions** — NOT affected (used `Object.create(null)` for initialization, no `|| {}` reassignment)
- The vulnerab
GHSA
DOMpurify has a nesting-based mXSS
ghsa·2024-10-11·CVSS 6.1
CVE-2024-47875 [MEDIUM] CWE-79 DOMpurify has a nesting-based mXSS
DOMpurify has a nesting-based mXSS
DOMpurify was vulnerable to nesting-based mXSS
fixed by [0ef5e537](https://github.com/cure53/DOMPurify/tree/0ef5e537a514f904b6aa1d7ad9e749e365d7185f) (2.x) and
[merge 943](https://github.com/cure53/DOMPurify/pull/943)
Backporter should be aware of GHSA-mmhx-hmjr-r674 (CVE-2024-45801) when cherry-picking
POC is avaible under [test](https://github.com/cure53/DOMPurify/blob/0ef5e537a514f904b6aa1d7ad9e749e365d7185f/test/test-suite.js#L2098)
OSV
DOMpurify has a nesting-based mXSS
osv·2024-10-11·CVSS 6.1
CVE-2024-47875 [MEDIUM] DOMpurify has a nesting-based mXSS
DOMpurify has a nesting-based mXSS
DOMpurify was vulnerable to nesting-based mXSS
fixed by [0ef5e537](https://github.com/cure53/DOMPurify/tree/0ef5e537a514f904b6aa1d7ad9e749e365d7185f) (2.x) and
[merge 943](https://github.com/cure53/DOMPurify/pull/943)
Backporter should be aware of GHSA-mmhx-hmjr-r674 (CVE-2024-45801) when cherry-picking
POC is avaible under [test](https://github.com/cure53/DOMPurify/blob/0ef5e537a514f904b6aa1d7ad9e749e365d7185f/test/test-suite.js#L2098)
GHSA
DOMPurify allows tampering by prototype pollution
ghsa·2024-09-16
CVE-2024-45801 [HIGH] CWE-1321 DOMPurify allows tampering by prototype pollution
DOMPurify allows tampering by prototype pollution
It has been discovered that malicious HTML using special nesting techniques can bypass the depth checking added to DOMPurify in recent releases. It was also possible to use Prototype Pollution to weaken the depth check.
This renders dompurify unable to avoid XSS attack.
Fixed by https://github.com/cure53/DOMPurify/commit/1e520262bf4c66b5efda49e2316d6d1246ca7b21 (3.x branch) and https://github.com/cure53/DOMPurify/commit/26e1d69ca7f769f5c558619d644d90dd8bf26ebc (2.x branch).
OSV
DOMPurify allows tampering by prototype pollution
osv·2024-09-16
CVE-2024-45801 [HIGH] DOMPurify allows tampering by prototype pollution
DOMPurify allows tampering by prototype pollution
It has been discovered that malicious HTML using special nesting techniques can bypass the depth checking added to DOMPurify in recent releases. It was also possible to use Prototype Pollution to weaken the depth check.
This renders dompurify unable to avoid XSS attack.
Fixed by https://github.com/cure53/DOMPurify/commit/1e520262bf4c66b5efda49e2316d6d1246ca7b21 (3.x branch) and https://github.com/cure53/DOMPurify/commit/26e1d69ca7f769f5c558619d644d90dd8bf26ebc (2.x branch).
OSV
CVE-2024-45801: DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG
osv·2024-09-16·CVSS 6.1
CVE-2024-45801 [MEDIUM] CVE-2024-45801: DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It has been discovered that malicious HTML using special nesting techniques can bypass the depth checking added to DOMPurify in recent releases. It was also possible to use Prototype Pollution to weaken the depth check. This renders dompurify unable to avoid cross site scripting (XSS) attacks. This issue has been addressed in versions 2.5.4 and 3.1.3 of DOMPurify. All users are advised to upgrade. There are no known workarounds for this vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-09-16
Published