CVE-2026-65900

Aliases:UBUNTU-CVE-2026-65900DEBIAN-CVE-2026-65900GHSA-gvmj-g25r-r7wrCGA-237g-69x8-42xgCGA-342g-6h2q-8484CGA-7hph-7r5f-wx3hCGA-8239-775h-2jv7CGA-8v5c-65qq-xpprCGA-ch93-qg7j-5f3mCGA-fh2w-9crx-j2rmCGA-gfqr-6g6g-28fxCGA-26mq-g834-5vpwCGA-2j2q-695h-3mwcCGA-2mfg-9cqm-x2w4CGA-2pff-6pff-7mm9CGA-2q7r-3fr2-hqjxCGA-2r6h-hmpr-986hCGA-37c5-x839-crv6CGA-37h2-qmx8-5p67CGA-3hf4-p557-px96CGA-3pjp-32j5-4q36CGA-3whv-w84g-gp33CGA-45h7-jj55-253rCGA-4px9-5mp6-mm5hCGA-54qr-64v6-ggf4CGA-55vr-h3x7-r5cfCGA-56jc-wwmh-hgjpCGA-59x8-vfhr-fwcqCGA-5cm2-m39g-5mv8CGA-5vxq-4jv5-fwghCGA-67f6-5gj2-x798CGA-685p-vpc6-v4xrCGA-6934-4v9c-pp2gCGA-6hmm-q443-3mjhCGA-6mmh-9v38-2h7jCGA-7292-vj3c-hg25CGA-76wg-gwj2-jwvrCGA-7frm-8hp9-jf4pCGA-7q36-5fpr-5jmfCGA-7xjp-v5vw-pgjgCGA-835x-jc7q-wp6wCGA-894x-jv6p-885wCGA-8fcj-qc3x-hgffCGA-8j28-3v69-5c7hCGA-8wx2-r6f3-5v5hCGA-8xw2-fq45-gh8jCGA-924c-39mq-pj4jCGA-9g2g-pq7v-hrg7CGA-c358-2hjp-m3fmCGA-c482-5fjq-wgh9CGA-c764-c929-8345CGA-c9hf-6v8h-frgvCGA-ccgg-rjmc-32vxCGA-ccwc-wpm2-627fCGA-cfr3-mg59-c6jvCGA-cjch-3qfx-xpx8CGA-cr42-g699-779rCGA-crg4-hmvc-fp4vCGA-fc69-h7pj-p9m2CGA-fffm-3jp4-r9hcCGA-fhhh-fwcc-wv3fCGA-fjxq-vxqg-x9qjCGA-fq3r-3wrg-p469CGA-fwvw-fxhm-m5ffCGA-g7v7-mr2q-h8jwCGA-gh2c-wj6r-9gh4CGA-h3gv-h2wm-vrh6CGA-h48m-hxhx-5mpjCGA-h82c-5gf3-w4x5CGA-hfmv-vccf-pj24CGA-hrfj-qjg9-f2jxCGA-hrvh-p598-qpr9CGA-hvh3-xpgr-gf38CGA-hx73-qfrg-r8qcCGA-j7rj-qmfx-vxrhCGA-jxxw-m2gw-gw5cCGA-m6pg-vcwx-7g8rCGA-m7qv-7rmp-73vpCGA-m8qf-g4jc-gj5fCGA-m925-h9v6-jvf3CGA-mc67-4r7c-cgr3CGA-mfwq-rxx6-cqmrCGA-mjp5-j578-pxhfCGA-mmqx-68f2-cw6xCGA-mqrm-rmrr-p2f8CGA-mrp8-g6fh-5hwqCGA-p6c5-xh43-g484CGA-p6p2-6fj5-68mwCGA-ppg3-5wmx-qm9fCGA-qm4f-mghr-jcfrCGA-qpg7-m2wj-449pCGA-qrx8-v298-jwp8CGA-r39g-h9vj-5v5rCGA-r87q-2cxx-h3fcCGA-rh2v-hq55-fqphCGA-v8qv-243x-h5m8CGA-v8rm-46vx-8hv9CGA-vjm5-6fg7-4c3vCGA-vjq5-r446-6cmgCGA-vvmm-p5px-m37gCGA-vwxm-959q-cch8CGA-w343-4q3v-g697CGA-w4x3-3m66-cffwCGA-w929-4h47-4hhwCGA-w92c-vqw9-7c5fCGA-wfvr-7f4f-v7wrCGA-wj5r-96xm-cc97CGA-wp59-r3mm-f72hCGA-wqmp-j6c6-cr4hCGA-x399-3836-8rj4CGA-x53j-vq62-pcqpCGA-x68q-ccpv-h389CGA-x9qm-wj3p-4rmjCGA-93r2-56v5-6xmp
Advisory lineage Upstream: 1 Downstream: 1
Analyzed
Published: 23 Jul 2026, 13:16
Last modified:23 Jul 2026, 18:02

Vulnerability Summary

Overall Risk (default)
medium
34/100
CVSS Score
6.1 MEDIUM
v3.1 (cve.org)
EPSS Score
0.21% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

23 Jul 2026, 13:16
Published
Vulnerability first disclosed
23 Jul 2026, 18:02
Last Modified
Vulnerability information updated

Description

DOMPurify versions >=3.0.0 and before 3.4.8, when configured with SAFE_FOR_TEMPLATES together with a DOM output mode (RETURN_DOM, RETURN_DOM_FRAGMENT, or IN_PLACE), fail to strip template expressions (e.g. ${evil}, {{evil}}, <%evil%>) inside <template> element content. The final normalization/scrub pass (_scrubTemplateExpressions) uses a NodeIterator and node.normalize() that do not descend into template.content, so expressions that only form after adjacent text nodes merge survive sanitization. This bypasses SAFE_FOR_TEMPLATES and can allow a downstream template engine to evaluate attacker-supplied expressions. The string output path is not affected.

CVSS Metrics

  • v4.0MEDIUMScore: 5.1CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
  • v4.0MEDIUMScore: 5.1CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v4.0MEDIUMScore: 5.1CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P
  • v3.1MEDIUMScore: 6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS Trends

Current EPSS score: 0.21% Percentile: 11%

Techniques & Countermeasures

  • CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Affected Systems

  • chainguardairflow-2

    all

  • chainguardairflow-core-2

    all

  • chainguardgitlab-rails-ce-18.1

    all

  • chainguardgitlab-rails-ce-18.10

    all

  • chainguardgitlab-rails-ce-18.11

    all

  • chainguardgitlab-rails-ce-18.5

    all

  • chainguardgitlab-rails-ce-18.6

    all

  • chainguardgitlab-rails-ce-18.7

    all

  • chainguardgitlab-rails-ce-18.8

    all

  • chainguardgitlab-rails-ce-18.9

    all

  • chainguardgitlab-rails-ce-19.0

    all

  • chainguardgitlab-rails-ce-19.1

    all | < 19.1.7-r6

  • chainguardgitlab-rails-ce-fips-18.1

    all

  • chainguardgitlab-rails-ce-fips-18.10

    all

  • chainguardgitlab-rails-ce-fips-18.11

    all

  • chainguardgitlab-rails-ce-fips-18.5

    all

  • chainguardgitlab-rails-ce-fips-18.6

    all

  • chainguardgitlab-rails-ce-fips-18.7

    all

  • chainguardgitlab-rails-ce-fips-18.8

    all

  • chainguardgitlab-rails-ce-fips-18.9

    all

  • chainguardgitlab-rails-ce-fips-19.0

    all

  • chainguardgitlab-rails-ce-fips-19.1

    all | < 19.1.7-r7

  • chainguardkibana-9.4

    < 9.4.2-r6

  • chainguardkibana-9.4-iamguarded

    < 9.4.2-r6

  • chainguardlangfuse-3-compat

    < 3.225.7-r6

  • chainguardlangfuse-3-worker

    < 3.191.0-r0

  • chainguardlangfuse-fips-3-worker

    < 3.192.0-r0

  • chainguardlibrechat

    < 0.8.7-r1

  • chainguardnextcloud-server-31

    all

  • chainguardnextcloud-server-32

    < 32.0.12-r0

  • chainguardnextcloud-server-33

    < 33.0.6-r0

  • chainguardnextcloud-server-34

    < 34.0.1-r4

  • chainguardwazuh-dashboard

    < 4.14.5-r7

  • chainguardwazuh-dashboard-alerting-dashboards-plugin

    < 4.14.5-r7

  • chainguardwazuh-dashboard-alerting-dashboards-plugin-fips

    < 4.14.5-r7

  • chainguardwazuh-dashboard-anomaly-detection-dashboards-plugin

    < 4.14.5-r7

  • chainguardwazuh-dashboard-anomaly-detection-dashboards-plugin-fips

    < 4.14.5-r7

  • chainguardwazuh-dashboard-dashboards-maps

    < 4.14.5-r7

  • chainguardwazuh-dashboard-dashboards-maps-fips

    < 4.14.5-r7

  • chainguardwazuh-dashboard-dashboards-notifications

    < 4.14.5-r7

  • chainguardwazuh-dashboard-dashboards-notifications-fips

    < 4.14.5-r7

  • chainguardwazuh-dashboard-dashboards-reporting

    < 4.14.5-r7

  • chainguardwazuh-dashboard-dashboards-reporting-fips

    < 4.14.5-r7

  • chainguardwazuh-dashboard-dashboards-visualizations

    < 4.14.5-r7

  • chainguardwazuh-dashboard-dashboards-visualizations-fips

    < 4.14.5-r7

  • chainguardwazuh-dashboard-fips

    < 4.14.5-r7

  • chainguardwazuh-dashboard-index-management-dashboards-plugin

    < 4.14.5-r7

  • chainguardwazuh-dashboard-index-management-dashboards-plugin-fips

    < 4.14.5-r7

  • chainguardwazuh-dashboard-plugins

    < 4.14.5-r7

  • chainguardwazuh-dashboard-plugins-fips

    < 4.14.5-r7

Showing first 50 affected entries in server-rendered view.

References (8)