CVE-2026-66010
published 2026-07-24CVE-2026-66010: DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes…
PriorityP428medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.17%
6.4th percentile
DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attributes on custom elements that later re-inject them into innerHTML sinks, creating second-order XSS gadgets.
Affected
53 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| 3scale-amp2 | system-rhel7 | — | — |
| 3scale-amp2 | system-rhel8 | — | — |
| 3scale-amp2 | system-rhel9 | — | — |
| 3scale-amp21 | system | — | — |
| 3scale-amp22 | system | — | — |
| advanced-cluster-security | rhacs-main-rhel8 | — | — |
| advanced-cluster-security | rhacs-main-rhel9 | — | — |
| ansible-automation-platform-26 | gateway-rhel9 | — | — |
| ansible-automation-platform-27 | gateway-rhel9 | — | — |
| ansible-automation-platform | automation-portal | — | — |
| apicurio | apicurio-registry-ui-rhel8 | — | — |
| apicurio | apicurio-registry-ui-rhel9 | — | — |
| container-native-virtualization | kubevirt-console-plugin | — | — |
| container-native-virtualization | kubevirt-console-plugin-rhel9 | — | — |
| cure53 | dompurify | < 3.4.12 | 3.4.12 |
| cure53 | dompurify | — | — |
| debian | ceph | — | — |
| devspaces | code-rhel9 | — | — |
| devspaces | openvsx-rhel9 | — | — |
| grafana | grafana | — | — |
| migration-toolkit-virtualization | mtv-console-plugin-rhel9 | — | — |
| multicluster-engine | console-mce-rhel9 | — | — |
| odf4 | ocs-client-console-rhel9 | — | — |
| odf4 | odf-console-rhel9 | — | — |
| odf4 | odf-multicluster-console-rhel9 | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv4.05.1MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
dompurify: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass
vendor_redhat·2026-07-24·CVSS 6.1
CVE-2026-66010 [MEDIUM] CWE-79 dompurify: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass
dompurify: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass
A flaw was found in DOMPurify. This vulnerability allows attackers to bypass application security policies by preserving sensitive attributes on custom elements. These attributes can then be re-injected into web page content, leading to Cross-Site Scripting (XSS) attacks. An attacker could exploit this to execute malicious scripts in a user's browser, potentially leading to information disclosure or unauthorized actions.
Statement: This Moderate-impact flaw in DOMPurify allows for Cross-Site Scripting (XSS) attacks by enabling the bypass of sanitization policies for custom elements. An attacker could exploit this by crafting malicious content that, when processed by affected Red Hat products utilizing DO
GHSA
DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies.
ghsa_unreviewed·2026-07-24
CVE-2026-66010 [MEDIUM] CWE-79 DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies.
DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attributes on custom elements that later re-inject them into innerHTML sinks, creating second-order XSS gadgets.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-66010 jupyterlab: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [fedora-all]
bugzilla·2026-07-24·CVSS 6.1
CVE-2026-66010 [MEDIUM] CVE-2026-66010 jupyterlab: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [fedora-all]
CVE-2026-66010 jupyterlab: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attributes on custom elements that later re-inject them into innerHTML sinks, creating second-order XSS gadgets.
Bugzilla
CVE-2026-66010 fbthrift: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [epel-all]
bugzilla·2026-07-24·CVSS 6.1
CVE-2026-66010 [MEDIUM] CVE-2026-66010 fbthrift: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [epel-all]
CVE-2026-66010 fbthrift: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attributes on custom elements that later re-inject them into innerHTML sinks, creating second-order XSS gadgets.
Bugzilla
CVE-2026-66010 cachelib: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [epel-all]
bugzilla·2026-07-24·CVSS 6.1
CVE-2026-66010 [MEDIUM] CVE-2026-66010 cachelib: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [epel-all]
CVE-2026-66010 cachelib: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attributes on custom elements that later re-inject them into innerHTML sinks, creating second-order XSS gadgets.
Bugzilla
CVE-2026-66010 grafana: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [fedora-all]
bugzilla·2026-07-24·CVSS 6.1
CVE-2026-66010 [MEDIUM] CVE-2026-66010 grafana: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [fedora-all]
CVE-2026-66010 grafana: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attributes on custom elements that later re-inject them into innerHTML sinks, creating second-order XSS gadgets.
Bugzilla
CVE-2026-66010 forgejo: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [epel-all]
bugzilla·2026-07-24·CVSS 6.1
CVE-2026-66010 [MEDIUM] CVE-2026-66010 forgejo: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [epel-all]
CVE-2026-66010 forgejo: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attributes on custom elements that later re-inject them into innerHTML sinks, creating second-order XSS gadgets.
Bugzilla
CVE-2026-66010 cachelib: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [fedora-all]
bugzilla·2026-07-24·CVSS 6.1
CVE-2026-66010 [MEDIUM] CVE-2026-66010 cachelib: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [fedora-all]
CVE-2026-66010 cachelib: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attributes on custom elements that later re-inject them into innerHTML sinks, creating second-order XSS gadgets.
Bugzilla
CVE-2026-66010 python-ipyparallel: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [fedora-all]
bugzilla·2026-07-24·CVSS 6.1
CVE-2026-66010 [MEDIUM] CVE-2026-66010 python-ipyparallel: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [fedora-all]
CVE-2026-66010 python-ipyparallel: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attributes on custom elements that later re-inject them into innerHTML sinks, creating second-order XSS gadgets.
Bugzilla
CVE-2026-66010 forgejo: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [fedora-all]
bugzilla·2026-07-24·CVSS 6.1
CVE-2026-66010 [MEDIUM] CVE-2026-66010 forgejo: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [fedora-all]
CVE-2026-66010 forgejo: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attributes on custom elements that later re-inject them into innerHTML sinks, creating second-order XSS gadgets.
Bugzilla
CVE-2026-66010 dompurify: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass
bugzilla·2026-07-24·CVSS 6.1
CVE-2026-66010 [MEDIUM] CVE-2026-66010 dompurify: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass
CVE-2026-66010 dompurify: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass
DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attributes on custom elements that later re-inject them into innerHTML sinks, creating second-order XSS gadgets.
Bugzilla
CVE-2026-66010 python-jupytext: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [fedora-all]
bugzilla·2026-07-24·CVSS 6.1
CVE-2026-66010 [MEDIUM] CVE-2026-66010 python-jupytext: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [fedora-all]
CVE-2026-66010 python-jupytext: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attributes on custom elements that later re-inject them into innerHTML sinks, creating second-order XSS gadgets.
Bugzilla
CVE-2026-66010 ansible-collection-awx-awx: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [epel-all]
bugzilla·2026-07-24·CVSS 6.1
CVE-2026-66010 [MEDIUM] CVE-2026-66010 ansible-collection-awx-awx: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [epel-all]
CVE-2026-66010 ansible-collection-awx-awx: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attributes on custom elements that later re-inject them into innerHTML sinks, creating second-order XSS gadgets.
Bugzilla
CVE-2026-66010 openbao: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [epel-all]
bugzilla·2026-07-24·CVSS 6.1
CVE-2026-66010 [MEDIUM] CVE-2026-66010 openbao: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [epel-all]
CVE-2026-66010 openbao: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attributes on custom elements that later re-inject them into innerHTML sinks, creating second-order XSS gadgets.
Bugzilla
CVE-2026-66010 nodejs-aw-webui: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [fedora-all]
bugzilla·2026-07-24·CVSS 6.1
CVE-2026-66010 [MEDIUM] CVE-2026-66010 nodejs-aw-webui: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [fedora-all]
CVE-2026-66010 nodejs-aw-webui: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attributes on custom elements that later re-inject them into innerHTML sinks, creating second-order XSS gadgets.
Bugzilla
CVE-2026-66010 fbthrift: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [fedora-all]
bugzilla·2026-07-24·CVSS 6.1
CVE-2026-66010 [MEDIUM] CVE-2026-66010 fbthrift: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [fedora-all]
CVE-2026-66010 fbthrift: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attributes on custom elements that later re-inject them into innerHTML sinks, creating second-order XSS gadgets.
Bugzilla
CVE-2026-66010 openbao: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [fedora-all]
bugzilla·2026-07-24·CVSS 6.1
CVE-2026-66010 [MEDIUM] CVE-2026-66010 openbao: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [fedora-all]
CVE-2026-66010 openbao: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attributes on custom elements that later re-inject them into innerHTML sinks, creating second-order XSS gadgets.
Bugzilla
CVE-2026-66010 nextcloud: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [fedora-all]
bugzilla·2026-07-24·CVSS 6.1
CVE-2026-66010 [MEDIUM] CVE-2026-66010 nextcloud: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [fedora-all]
CVE-2026-66010 nextcloud: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attributes on custom elements that later re-inject them into innerHTML sinks, creating second-order XSS gadgets.
Bugzilla
CVE-2026-66010 jupyterlab: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [epel-all]
bugzilla·2026-07-24·CVSS 6.1
CVE-2026-66010 [MEDIUM] CVE-2026-66010 jupyterlab: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [epel-all]
CVE-2026-66010 jupyterlab: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attributes on custom elements that later re-inject them into innerHTML sinks, creating second-order XSS gadgets.
2026-07-24
Published