cbcvebase.

Debian Node-Dompurify vulnerabilities

6 known vulnerabilities affecting debian/node-dompurify.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH1MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2024-48910P3CRITICALCVSS 9.1fixed in cacti 1.2.24+ds1-1+deb12u2 (bookworm)2024
CVE-2024-48910 [CRITICAL] CVE-2024-48910: cacti - DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathM... DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to prototype pollution. This vulnerability is fixed in 2.4.2. Scope: local bookworm: resolved (fixed in 1.2.24+ds1-1+deb12u2) bullseye: resolved (fixed in 1.2.16+ds1-2+deb11u5) forky: resolved (fixed in 1.2.26+ds1-1) sid: resolved (fixed in 1.2.26+ds
debian
CVE-2026-0540P4MEDIUMCVSS 5.3fixed in node-dompurify 3.3.2+dfsg-1 (forky)2026
CVE-2026-0540 [MEDIUM] CVE-2026-0540: node-dompurify - DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 2726c74, ... DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 2726c74, contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting five missing rawtext elements (noscript, xmp, noembed, noframes, iframe) in the SAFE_FOR_XML regex. Attackers can include payloads like in attribute values to execute
debian
CVE-2024-45801P4HIGHCVSS 7.3fixed in node-dompurify 2.4.1+dfsg+~2.4.0-2+deb12u1 (bookworm)2024
CVE-2024-45801 [HIGH] CVE-2024-45801: node-dompurify - DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathM... DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It has been discovered that malicious HTML using special nesting techniques can bypass the depth checking added to DOMPurify in recent releases. It was also possible to use Prototype Pollution to weaken the depth check. This renders dompurify unable to avoid cross site
debian
CVE-2025-15599P4MEDIUMCVSS 5.1fixed in node-dompurify 3.3.2+dfsg-1 (forky)2025
CVE-2025-15599 [MEDIUM] CVE-2025-15599: node-dompurify - DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scrip... DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting missing textarea rawtext element validation in the SAFE_FOR_XML regex. Attackers can include closing rawtext tags like in attribute values to break out of rawtext contexts and execute JavaScr
debian
CVE-2024-47875P4CRITICALCVSS 10.0fixed in cacti 1.2.24+ds1-1+deb12u2 (bookworm)2024
CVE-2024-47875 [CRITICAL] CVE-2024-47875: cacti - DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathM... DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3. Scope: local bookworm: resolved (fixed in 1.2.24+ds1-1+deb12u2) bullseye: resolved (fixed in 1.2.16+ds1-2+deb11u5) forky: resolved (fixed in 1.2.26+ds1-1) sid: resolved (fixed in
debian
CVE-2025-26791P4MEDIUMCVSS 4.5fixed in node-dompurify 3.1.7+dfsg+~3.0.5-2 (forky)2025
CVE-2025-26791 [MEDIUM] CVE-2025-26791: node-dompurify - DOMPurify before 3.2.4 has an incorrect template literal regular expression, som... DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS). Scope: local bookworm: open forky: resolved (fixed in 3.1.7+dfsg+~3.0.5-2) sid: resolved (fixed in 3.1.7+dfsg+~3.0.5-2) trixie: resolved (fixed in 3.1.7+dfsg+~3.0.5-2)
debian
Debian Node-Dompurify vulnerabilities | cvebase