CVE-2026-65899

MEDIUM

DOMPurify before 3.4.9 Trusted Types Policy State Contamination

Title source: cna
STIX 2.1

Description

DOMPurify 3.0.0 before 3.4.9 does not reset the retained Trusted Types policy when clearConfig() is called, so a DOMPurify instance reused across trust boundaries stays bound to a previously supplied TRUSTED_TYPES_POLICY. A later caller that requests RETURN_TRUSTED_TYPE output receives a TrustedHTML object created by the old (potentially unsafe) policy rather than a clean default, which can lead to script execution at a Trusted Types sink. Passing TRUSTED_TYPES_POLICY: null on the later call also does not clear the retained policy.

References (3)

Core 3
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-vxr8-fq34-vvx9)
https://github.com/cure53/DOMPurify/security/advisories/GHSA-vxr8-fq34-vvx9
Third Party Advisory third-party-advisory
VulnCheck Advisory: DOMPurify before 3.4.9 Trusted Types Policy State Contamination
https://www.vulncheck.com/advisories/dompurify-before-trusted-types-policy-state-contamination

Scores

CVSS v3 6.1
EPSS 0.0023
EPSS Percentile 14.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-693
Status published
Products (4)
cure53/DOMPurify < 3.4.9
cure53/dompurify 3.0.0 - 3.4.9
cure53/DOMPurify 3.4.9
npm/dompurify 0 - 3.4.9npm
Published Jul 23, 2026
Tracked Since Jul 23, 2026