cbcvebase.
CVE-2026-41239
published 2026-04-23

CVE-2026-41239: DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in version 1.0.10 and prior to version 3.4.0, `SAFE_FOR_TEMPLATES`…

PriorityP430medium6.8CVSS 3.1
AVNACHPRNUIRSUCHIHAN
EPSS
0.25%
16.2th percentile
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in version 1.0.10 and prior to version 3.4.0, `SAFE_FOR_TEMPLATES` strips `{{...}}` expressions from untrusted HTML. This works in string mode but not with `RETURN_DOM` or `RETURN_DOM_FRAGMENT`, allowing XSS via template-evaluating frameworks like Vue 2. Version 3.4.0 patches the issue.

Affected

47 ranges· showing 25
VendorProductVersion rangeFixed in
3scale-amp2system-rhel7
3scale-amp2system-rhel8
3scale-amp2system-rhel9
3scale-amp21system
3scale-amp22system
advanced-cluster-securityrhacs-main-rhel8
ansible-automation-platform-26gateway-rhel9
ansible-automation-platformautomation-portal
apicurioapicurio-registry-ui-rhel8
apicurioapicurio-registry-ui-rhel9
container-native-virtualizationkubevirt-console-plugin
container-native-virtualizationkubevirt-console-plugin-rhel9
cure53dompurify
cure53dompurify
cure53dompurify>= 1.0.10 < 3.4.03.4.0
devspacescode-rhel9
devspacesopenvsx-rhel9
grafanagrafana
migration-toolkit-virtualizationmtv-console-plugin-rhel9
mtv-candidatemtv-console-plugin-rhel9
multicluster-engineconsole-mce-rhel9
odf4ocs-client-console-rhel9
odf4odf-console-rhel8
odf4odf-console-rhel9
odf4odf-multicluster-console-rhel8

CVSS provenance

nvdv3.16.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.