CVE-2026-65899
MEDIUMDOMPurify before 3.4.9 Trusted Types Policy State Contamination
Title source: cnaDescription
DOMPurify 3.0.0 before 3.4.9 does not reset the retained Trusted Types policy when clearConfig() is called, so a DOMPurify instance reused across trust boundaries stays bound to a previously supplied TRUSTED_TYPES_POLICY. A later caller that requests RETURN_TRUSTED_TYPE output receives a TrustedHTML object created by the old (potentially unsafe) policy rather than a clean default, which can lead to script execution at a Trusted Types sink. Passing TRUSTED_TYPES_POLICY: null on the later call also does not clear the retained policy.
References (3)
Core 3
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-vxr8-fq34-vvx9)
https://github.com/cure53/DOMPurify/security/advisories/GHSA-vxr8-fq34-vvx9
Third Party Advisory third-party-advisory
VulnCheck Advisory: DOMPurify before 3.4.9 Trusted Types Policy State Contamination
https://www.vulncheck.com/advisories/dompurify-before-trusted-types-policy-state-contamination
Scores
CVSS v3
6.1
EPSS
0.0023
EPSS Percentile
14.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-693
Status
published
Products (4)
cure53/DOMPurify
< 3.4.9
cure53/dompurify
3.0.0 - 3.4.9
cure53/DOMPurify
3.4.9
npm/dompurify
0 - 3.4.9npm
Published
Jul 23, 2026
Tracked Since
Jul 23, 2026