CVE-2026-65898

Aliases:UBUNTU-CVE-2026-65898DEBIAN-CVE-2026-65898GHSA-cmwh-pvxp-8882CGA-5w9m-j9q9-68qfCGA-7cq4-r555-xp5pCGA-7gwc-jcgf-r764CGA-c529-qmpx-7995CGA-h264-rmvq-xfrxCGA-m3xx-7h4p-5jcgCGA-pm8r-x967-rp73CGA-22m9-4cw5-xfhqCGA-249j-9wv9-w23jCGA-24q8-39jq-fw4wCGA-29cg-mx8v-ffg7CGA-2fp3-jxx7-244gCGA-2jch-h783-wqp2CGA-2jhq-38mc-jgq2CGA-32wm-p7h4-vxpqCGA-35x8-jcgv-rxf9CGA-3h9g-2f2w-p3v2CGA-3j5m-6g2w-qmcgCGA-3prp-324v-f3pwCGA-3qmq-gvc9-8vp5CGA-3x88-g2wx-wp2rCGA-492m-7436-9295CGA-4949-6ch2-9355CGA-4hg8-jfgw-cj2hCGA-4p7c-g82r-738cCGA-4p7q-cp87-9cfqCGA-4p8r-r99j-ffhfCGA-4v4c-9c56-6g2gCGA-4vx2-gfv4-r83mCGA-4wvm-26f5-9qv7CGA-553h-r5m2-vfw7CGA-56q2-fx28-gwjqCGA-5gm9-x54p-326hCGA-5hp4-m67x-w2qqCGA-5p6x-f9ff-8rqhCGA-5r38-725x-h9r4CGA-5vwf-jj9r-p844CGA-5x6c-p5x8-2gh3CGA-65xp-jj64-3gcwCGA-66h3-gj7x-qfffCGA-6h85-ff34-j3wpCGA-6jmh-22fx-8975CGA-6m67-pph4-3377CGA-6m9p-3h76-hmj8CGA-6p67-jxm4-267hCGA-6rc3-pfm4-9hrrCGA-765c-52q5-wq2pCGA-78hr-6cj5-f3pmCGA-7j4p-27qg-4v4cCGA-7j9h-2rj3-w235CGA-7q33-58m4-pw8jCGA-7qhh-m7q6-2j34CGA-7v3h-wqjv-96vfCGA-7x6x-p3rx-4xpjCGA-7x87-6qfh-22hqCGA-7xx6-g7pf-cg5mCGA-8293-rqcq-pcf9CGA-84px-39rr-xg57CGA-8fqp-h8rm-qv6vCGA-8hgx-gr63-xgpcCGA-8j7r-hc2m-xc4mCGA-8qr4-385r-9mxrCGA-8vc8-xxr3-5qhqCGA-8w4q-29x9-w236CGA-8wpp-ghc2-fxfxCGA-8x5m-5hrq-5rh9CGA-8x7f-6f42-6f79CGA-97x4-73v7-9h3xCGA-9gjj-p2gp-5xp6CGA-9j4g-xmx5-gpmxCGA-9m2x-5f8q-gjq4CGA-9wff-q9rw-qg5fCGA-c2hc-q4px-vfv4CGA-c77m-rgp7-6cv5CGA-chx7-fxrc-gx7cCGA-cxhf-wj7j-qj56CGA-f2hq-6hjr-22hgCGA-f2mf-mqw7-v9c8CGA-f4jc-748h-qjpmCGA-f8fv-q272-28crCGA-fcqp-x698-qjfjCGA-ffv9-2xw9-3rmmCGA-fgcx-v2cw-h7xwCGA-fp3q-734j-5p98CGA-fqx9-q23j-6r5fCGA-fr48-8248-ch8vCGA-fv5c-hqpq-5w2vCGA-fv84-whm7-7x42CGA-g68v-2hq2-fjfjCGA-g88w-x32j-939xCGA-g8j7-pm78-4r43CGA-gggh-mf68-mqwjCGA-gp4x-xf3f-v5j9CGA-gwmw-gjx5-4rwqCGA-hc9c-4whm-p2qqCGA-hxch-r253-w6p6CGA-hxjc-mw3p-g9m8CGA-j2c5-r42f-4xjjCGA-j56m-v9c2-wwjwCGA-j8wp-3fjv-62j2CGA-jjjv-c7j8-7mjfCGA-jrgh-v39r-xhw4CGA-m6qw-g46q-6mjcCGA-m8w6-ccrv-q4w6CGA-m9hx-hx98-cwgmCGA-mcc7-xrr8-58h6CGA-mf92-88rg-9v47CGA-mh2v-h4ch-w4jhCGA-mjwx-38rh-pg3gCGA-mv98-w66f-jw2mCGA-p288-wwjr-3v5qCGA-p84v-c6w7-cg2qCGA-pjx5-wmrg-297hCGA-pm8h-3wrh-2325CGA-pw9p-wfq3-96xvCGA-pwg2-758p-2qvfCGA-q3vw-mhvc-2q84CGA-q9x5-xg7w-gmv8CGA-qf7g-32hp-6qrgCGA-qgqh-g435-6q62CGA-qhv4-5xr2-vm9xCGA-qq2m-52vg-hqgmCGA-qq39-jh4h-rmxqCGA-qq59-2937-vfjjCGA-qr54-72w3-66rhCGA-qr6w-g7rc-w5w5CGA-qvf4-3w4c-28vcCGA-r3qh-jf6v-3q62CGA-r55m-gr24-7w24CGA-r5fr-46gm-h86gCGA-r663-vhxr-p2vcCGA-r89p-vx69-3gr5CGA-r992-95xp-3mrhCGA-r9f5-6x87-pfgcCGA-rf3v-cvxr-3wcfCGA-rfmq-9xvv-2xr4CGA-rgh2-7x5j-78vmCGA-rjf8-9fj8-jc2vCGA-rm78-6rhm-6h92CGA-rp44-376w-cfmhCGA-rq5r-893x-v972CGA-rqph-jg9j-76ccCGA-rwwq-pqrg-x9gqCGA-rxh6-h6xp-p6x5CGA-v233-7rxp-mc2wCGA-v833-3q7w-3gphCGA-vfpm-gcv6-mwghCGA-vgvw-mw3h-hxgjCGA-vjfm-fqp7-38r8CGA-vpfq-cvgq-q2mjCGA-vpq7-925c-9gh9CGA-vpr8-7p97-629rCGA-vqwr-mcwf-4w4xCGA-vv4r-2qg2-pg29CGA-vx3f-6crw-6g5wCGA-w4rc-278w-8j59CGA-w554-q5x4-5g53CGA-wc6g-8v78-g7pwCGA-wcgq-2v3x-64p6CGA-wcx5-ffv2-w5j7CGA-whc5-qmqc-9f7vCGA-whxq-f7vx-p522CGA-wjpv-28jj-3636CGA-wp2x-3f5x-f4cmCGA-wvfc-r72f-c2rcCGA-wvqv-jqw2-2vmfCGA-x2fj-x93h-jp7rCGA-x746-x2q6-pfpwCGA-x858-3f34-m9v3CGA-x883-xf5g-xjhmCGA-x8pw-637p-wg99CGA-x9fg-5h2x-2gprCGA-xq8p-hxmg-p9gcCGA-xxvw-54g9-hhw9CGA-p2x6-fp3r-xm86
Advisory lineage Upstream: 1 Downstream: 3
Analyzed
Published: 23 Jul 2026, 13:16
Last modified:23 Jul 2026, 15:47

Vulnerability Summary

Overall Risk (default)
medium
39/100
CVSS Score
7.2 HIGH
v3.1 (cve.org)
EPSS Score
0.21% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

23 Jul 2026, 13:16
Published
Vulnerability first disclosed
23 Jul 2026, 15:47
Last Modified
Vulnerability information updated

Description

DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute hook, allowing the hook to permanently mutate the shared allowlist. Attackers can register a hook that conditionally allows dangerous attributes like onerror for trusted elements, then submit untrusted content that inherits the polluted allowlist and executes event handlers as stored XSS.

CVSS Metrics

  • v4.0MEDIUMScore: 5.1CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
  • v4.0MEDIUMScore: 5.1CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.1HIGHScore: 7.2CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

EPSS Trends

Current EPSS score: 0.21% Percentile: 12%

Techniques & Countermeasures

  • CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Affected Systems

  • chainguardairflow-2

    all

  • chainguardairflow-core-2

    all

  • chainguardgitlab-rails-ce-18.1

    all

  • chainguardgitlab-rails-ce-18.10

    all

  • chainguardgitlab-rails-ce-18.11

    all

  • chainguardgitlab-rails-ce-18.5

    all

  • chainguardgitlab-rails-ce-18.6

    all

  • chainguardgitlab-rails-ce-18.7

    all

  • chainguardgitlab-rails-ce-18.8

    all

  • chainguardgitlab-rails-ce-18.9

    all

  • chainguardgitlab-rails-ce-19.0

    all

  • chainguardgitlab-rails-ce-19.1

    all | < 19.1.7-r6

  • chainguardgitlab-rails-ce-fips-18.1

    all

  • chainguardgitlab-rails-ce-fips-18.10

    all

  • chainguardgitlab-rails-ce-fips-18.11

    all

  • chainguardgitlab-rails-ce-fips-18.5

    all

  • chainguardgitlab-rails-ce-fips-18.6

    all

  • chainguardgitlab-rails-ce-fips-18.7

    all

  • chainguardgitlab-rails-ce-fips-18.8

    all

  • chainguardgitlab-rails-ce-fips-18.9

    all

  • chainguardgitlab-rails-ce-fips-19.0

    all

  • chainguardgitlab-rails-ce-fips-19.1

    all | < 19.1.7-r7

  • chainguardkibana-9.4

    < 9.4.2-r6

  • chainguardkibana-9.4-iamguarded

    < 9.4.2-r6

  • chainguardlangfuse-2

    < 2.95.12-r31

  • chainguardlangfuse-2-worker

    < 2.95.12-r31

  • chainguardlangfuse-3-compat

    < 3.225.7-r6

  • chainguardlangfuse-3-worker

    < 3.197.1-r0

  • chainguardlangfuse-fips-2

    < 2.95.12-r33

  • chainguardlangfuse-fips-2-worker

    < 2.95.12-r33

  • chainguardlangfuse-fips-3-worker

    < 3.197.0-r0

  • chainguardlibrechat

    < 0.8.7-r4

  • chainguardnextcloud-server-31

    all

  • chainguardnextcloud-server-32

    < 32.0.12-r4

  • chainguardnextcloud-server-33

    < 33.0.6-r5

  • chainguardnextcloud-server-34

    < 34.0.1-r4

  • chainguardopensearch-dashboards-2

    < 2.19.5-r15

  • chainguardopensearch-dashboards-2-alerting-dashboards-plugin

    < 2.19.5-r15

  • chainguardopensearch-dashboards-2-anomaly-detection-dashboards-plugin

    < 2.19.5-r15

  • chainguardopensearch-dashboards-2-dashboards-maps

    < 2.19.5-r15

  • chainguardopensearch-dashboards-2-dashboards-notifications

    < 2.19.5-r15

  • chainguardopensearch-dashboards-2-dashboards-observability

    < 2.19.5-r15

  • chainguardopensearch-dashboards-2-dashboards-query-workbench

    < 2.19.5-r15

  • chainguardopensearch-dashboards-2-dashboards-reporting

    < 2.19.5-r15

  • chainguardopensearch-dashboards-2-dashboards-search-relevance

    < 2.19.5-r15

  • chainguardopensearch-dashboards-2-dashboards-visualizations

    < 2.19.5-r15

  • chainguardopensearch-dashboards-2-index-management-dashboards-plugin

    < 2.19.5-r15

  • chainguardopensearch-dashboards-2-ml-commons-dashboards

    < 2.19.5-r15

  • chainguardopensearch-dashboards-2-security-analytics-dashboards-plugin

    < 2.19.5-r15

  • chainguardopensearch-dashboards-2-security-dashboards-plugin

    < 2.19.5-r15

Showing first 50 affected entries in server-rendered view.

References (11)