cbcvebase.
CVE-2026-49458
published 2026-07-14

CVE-2026-49458: DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(node, { IN_PLACE: true }) accepted…

PriorityP427medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.38%
30.9th percentile
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(node, { IN_PLACE: true }) accepted same-origin foreign-realm DOM nodes while follow-on checks used parent-realm constructors, causing instanceof checks for forms, named node maps, document fragments, and elements to fail and skip clobber, template-content, and shadow-DOM sanitization branches so executable markup could survive. This issue is fixed in version 3.4.6.

Affected

46 ranges· showing 25
VendorProductVersion rangeFixed in
advanced-cluster-securityrhacs-main-rhel8
advanced-cluster-securityrhacs-main-rhel9
ansible-automation-platform-26gateway-rhel9
ansible-automation-platform-27gateway-rhel9
ansible-automation-platformautomation-portal
container-native-virtualizationkubevirt-console-plugin
container-native-virtualizationkubevirt-console-plugin-rhel9
cure53dompurify< 3.4.63.4.6
cure53dompurify
cure53dompurify>= 0 < 3.4.63.4.6
devspacescode-rhel9
devspacesopenvsx-rhel9
migration-toolkit-virtualizationmtv-console-plugin-rhel9
mtv-candidatemtv-console-plugin-rhel9
multicluster-engineconsole-mce-rhel9
odf4ocs-client-console-rhel9
odf4odf-console-rhel9
odf4odf-multicluster-console-rhel9
openshift-gitops-1argocd-rhel8
openshift-gitops-1argocd-rhel9
openshift-lightspeedlightspeed-agentic-console-rhel9
openshift-lightspeedlightspeed-console-plugin-419-rhel9
openshift-lightspeedlightspeed-console-plugin-pf5-rhel9
openshift-lightspeedlightspeed-console-plugin-rhel9
openshift-service-meshkiali-ossmc-rhel9

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.