CVE-2026-65899

Aliases:UBUNTU-CVE-2026-65899DEBIAN-CVE-2026-65899GHSA-vxr8-fq34-vvx9CGA-2jjw-q9hq-jgw8CGA-2m57-v9pp-rpcwCGA-4qq2-hghf-fq6mCGA-5hg4-x99f-g28qCGA-5w25-hvhf-p4jvCGA-6ghh-93gr-7r3jCGA-6v3p-7hm4-r9hgCGA-87hx-66p6-wh64CGA-8c9w-gv9v-h6hjCGA-8fhm-x4q8-x7mmCGA-8jqr-g5fw-8wqpCGA-8qfr-3hq4-jr36CGA-8xj2-83f4-8f5xCGA-9f6f-337m-q5q8CGA-c29v-5rmp-qv3hCGA-cgr5-cq9p-57ghCGA-cm7j-27wr-x387CGA-h4q9-6pgm-hhxqCGA-hhhj-89fg-m8fxCGA-j5w4-rh28-5957CGA-jf25-89x7-3wm6CGA-mjmh-7m3w-jhhwCGA-mqgj-hf4p-cxjcCGA-phf3-8q62-rp98CGA-pj63-g3cg-5vxxCGA-28hx-2q6r-8gpvCGA-2h2q-g5px-2cv3CGA-2m94-f3f6-hcw9CGA-2w84-hcgj-7j8wCGA-354c-pqjv-x9f6CGA-375r-p42h-vjr5CGA-3g3j-pppv-9p6jCGA-3pxq-rwfg-4h2cCGA-3qw9-6vh5-crjxCGA-3vc2-5v48-j4h5CGA-4h3r-5rgr-2h9pCGA-52h4-4c5x-h8q9CGA-5m86-35jm-m869CGA-5mfc-vxh3-88qrCGA-5p46-22c6-57grCGA-5q32-89r6-jp5wCGA-5xfq-67mv-3hxxCGA-636r-6f23-57m3CGA-64xh-9gqw-x99pCGA-66gm-g8fm-cfmwCGA-67rf-qvjc-c6cpCGA-694m-cg2v-9vvhCGA-6c4g-ffwx-v5v4CGA-6g53-wfcg-g3vcCGA-6mh2-fvgc-jr7pCGA-6q6w-x9jw-hxgxCGA-6w8v-qc27-45gwCGA-7494-cmvv-f32fCGA-75g9-9mqp-mv4pCGA-778m-4p6f-wgqvCGA-79c3-m2j2-jvw6CGA-7p4c-8rcx-mfm2CGA-7vvr-x9cc-g7xqCGA-7wfw-gqqv-pc67CGA-823r-v986-6m84CGA-87gq-26r8-2jx8CGA-8f33-9j82-p46vCGA-8pcc-4jqj-r4x3CGA-8wvc-q69x-7g89CGA-95j6-88g5-3qwxCGA-97x4-c828-677pCGA-9xvj-wxhx-m4vjCGA-c34m-34fp-9qm4CGA-c3fx-2vjg-whmcCGA-c3m5-x5mg-jgfjCGA-c57w-5jwx-7qq6CGA-c78g-4xjw-8xffCGA-cfr2-v3rq-666mCGA-cgrw-m82v-c9p9CGA-ch65-6876-85p7CGA-cmg6-8798-5hfqCGA-cv3x-cjxv-gpjfCGA-cvhc-jgjg-4w8cCGA-f5q9-39hq-gx4cCGA-fg5h-gvv7-9cxgCGA-fhcm-gjgm-q942CGA-fhwh-cqcf-5gh6CGA-fjq2-34mf-mc43CGA-fm86-q4cv-2v33CGA-fwcj-7qpg-c2qvCGA-g837-3m7r-3crrCGA-gg37-hxcj-82h6CGA-ghch-g387-5c9wCGA-gm7m-46j2-r2vvCGA-gvp8-5968-3pxjCGA-gxvj-5qgp-x9rxCGA-h468-hv59-4v8hCGA-h8qr-jggc-2chmCGA-hq4m-88m5-2xfqCGA-hrvc-c8mx-chrwCGA-j32r-6ch9-7ggwCGA-j5hg-h3v7-xj64CGA-j7qv-4rjw-9q49CGA-jhcw-3mpm-ppphCGA-jhjv-8595-4553CGA-jjxh-9vjf-2gmwCGA-jqm6-c998-x3mfCGA-m42v-c6q5-wwgfCGA-m6rv-w842-9c63CGA-mmq5-fmfc-hhq3CGA-p252-3x2x-xvq2CGA-pfrv-x6w3-3g26CGA-pph2-6686-5pfxCGA-prpf-8m8v-hrj2CGA-pv4q-fww9-v75fCGA-px28-25q4-2pgrCGA-q2xm-pj84-x458CGA-qf3j-rv8r-jmf6CGA-qhm7-frqx-c2hqCGA-qp93-r4mv-8vjrCGA-qq58-qxjc-pxm3CGA-r3mx-pf56-rgpcCGA-r4jx-xq38-9g5xCGA-r574-6h6j-j6ccCGA-rr46-f775-c9x9CGA-v27f-f7gf-rppwCGA-v2jq-6939-fffrCGA-v624-4p63-mrfqCGA-v788-ffj2-jvxwCGA-v7x2-cv97-x996CGA-vhc2-hrvf-xqp8CGA-vr2m-vxfc-j72mCGA-vrx5-843j-v4h2CGA-vwgx-w227-m7f2CGA-w463-353h-rhw5CGA-w5x7-vwrr-49g2CGA-w737-p9xg-3966CGA-w89m-g4fw-9wv4CGA-w8xc-65cv-6j6cCGA-w9qm-mq5v-p7w8CGA-wv5j-px35-c59rCGA-x7fm-q8c7-69v6CGA-x7jp-2537-8pr3CGA-x932-3chw-j598CGA-x999-hxjf-mvgcCGA-x9v4-7wv5-3jchCGA-xcqj-gx75-83qwCGA-xprc-2mx2-wwg6CGA-xqxv-2h4c-v9f9CGA-xr5w-rgqq-37cgCGA-xv66-4cxc-j5qvCGA-xvvg-p9xc-q3m2CGA-xvx9-q369-qg7pCGA-xw5h-m5v5-3qfgCGA-xxf5-x974-rcmcCGA-j6v4-439m-46p3
Advisory lineage Upstream: 1 Downstream: 3
Analyzed
Published: 23 Jul 2026, 13:16
Last modified:27 Jul 2026, 16:20

Vulnerability Summary

Overall Risk (default)
medium
34/100
CVSS Score
6.1 MEDIUM
v3.1 (cve.org)
EPSS Score
0.27% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

23 Jul 2026, 13:16
Published
Vulnerability first disclosed
27 Jul 2026, 16:20
Last Modified
Vulnerability information updated

Description

DOMPurify 3.0.0 before 3.4.9 does not reset the retained Trusted Types policy when clearConfig() is called, so a DOMPurify instance reused across trust boundaries stays bound to a previously supplied TRUSTED_TYPES_POLICY. A later caller that requests RETURN_TRUSTED_TYPE output receives a TrustedHTML object created by the old (potentially unsafe) policy rather than a clean default, which can lead to script execution at a Trusted Types sink. Passing TRUSTED_TYPES_POLICY: null on the later call also does not clear the retained policy.

CVSS Metrics

  • v4.0MEDIUMScore: 5.1CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
  • v4.0MEDIUMScore: 5.1CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v4.0LOWScore: 2.1CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
  • v3.1MEDIUMScore: 6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS Trends

Current EPSS score: 0.27% Percentile: 19%

Techniques & Countermeasures

  • CWE-693Protection Mechanism Failure

    The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

Affected Systems

  • chainguardairflow-2

    all

  • chainguardairflow-core-2

    all

  • chainguardgitlab-rails-ce-18.1

    all

  • chainguardgitlab-rails-ce-18.10

    all

  • chainguardgitlab-rails-ce-18.11

    all

  • chainguardgitlab-rails-ce-18.5

    all

  • chainguardgitlab-rails-ce-18.6

    all

  • chainguardgitlab-rails-ce-18.7

    all

  • chainguardgitlab-rails-ce-18.8

    all

  • chainguardgitlab-rails-ce-18.9

    all

  • chainguardgitlab-rails-ce-19.0

    all

  • chainguardgitlab-rails-ce-19.1

    all | < 19.1.7-r6

  • chainguardgitlab-rails-ce-fips-18.1

    all

  • chainguardgitlab-rails-ce-fips-18.10

    all

  • chainguardgitlab-rails-ce-fips-18.11

    all

  • chainguardgitlab-rails-ce-fips-18.5

    all

  • chainguardgitlab-rails-ce-fips-18.6

    all

  • chainguardgitlab-rails-ce-fips-18.7

    all

  • chainguardgitlab-rails-ce-fips-18.8

    all

  • chainguardgitlab-rails-ce-fips-18.9

    all

  • chainguardgitlab-rails-ce-fips-19.0

    all

  • chainguardgitlab-rails-ce-fips-19.1

    all | < 19.1.7-r7

  • chainguardkibana-9.1

    < 9.1.10-r20

  • chainguardkibana-9.1-iamguarded

    < 9.1.10-r20

  • chainguardkibana-9.2

    < 9.2.8-r8

  • chainguardkibana-9.2-iamguarded

    < 9.2.8-r8

  • chainguardkibana-9.3

    < 9.3.5-r3

  • chainguardkibana-9.3-iamguarded

    < 9.3.5-r3

  • chainguardkibana-9.4

    < 9.4.2-r6

  • chainguardkibana-9.4-iamguarded

    < 9.4.2-r6

  • chainguardlangfuse-3-compat

    < 3.225.7-r6

  • chainguardlangfuse-3-worker

    < 3.191.0-r0

  • chainguardlangfuse-fips-3-worker

    < 3.192.0-r0

  • chainguardlibrechat

    < 0.8.7-r1

  • chainguardnextcloud-server-31

    all

  • chainguardnextcloud-server-32

    < 32.0.12-r4

  • chainguardnextcloud-server-33

    < 33.0.6-r5

  • chainguardnextcloud-server-34

    < 34.0.1-r4

  • chainguardopensearch-dashboards-3

    < 3.7.0-r0

  • chainguardopensearch-dashboards-3-alerting-dashboards-plugin

    < 3.7.0-r0

  • chainguardopensearch-dashboards-3-anomaly-detection-dashboards-plugin

    < 3.7.0-r0

  • chainguardopensearch-dashboards-3-dashboards-maps

    < 3.7.0-r0

  • chainguardopensearch-dashboards-3-dashboards-notifications

    < 3.7.0-r0

  • chainguardopensearch-dashboards-3-dashboards-observability

    < 3.7.0-r0

  • chainguardopensearch-dashboards-3-dashboards-query-workbench

    < 3.7.0-r0

  • chainguardopensearch-dashboards-3-dashboards-reporting

    < 3.7.0-r0

  • chainguardopensearch-dashboards-3-dashboards-search-relevance

    < 3.7.0-r0

  • chainguardopensearch-dashboards-3-index-management-dashboards-plugin

    < 3.7.0-r0

  • chainguardopensearch-dashboards-3-ml-commons-dashboards

    < 3.7.0-r0

  • chainguardopensearch-dashboards-3-security-analytics-dashboards-plugin

    < 3.7.0-r0

Showing first 50 affected entries in server-rendered view.

References (9)