What is CVE-2026-65911?
CVE-2026-65911 affects DOMPurify up to version 3.3.3, where function predicates passed via `ADD_ATTR` or `ADD_TAGS` to `sanitize()` persist in internal state across subsequent calls on the same instance. This can lead to security issues when a later call uses an array instead of a function for these options. Users should update to the latest version.
Azərbaycanca: CVE-2026-65911 DOMPurify kitabxanasının 3.3.3 versiyasına qədər olan versiyalarında aşkarlanıb, burada `sanitize()` metoduna `ADD_ATTR` və ya `ADD_TAGS` vasitəsilə ötürülən funksiya predikatları daxili vəziyyətdə qalaraq növbəti çağırışlara təsir edir. Bu, xüsusilə sonrakı çağırışda array tipli parametr istifadə edildikdə təhlükəsizlik zəifliyinə səbəb ola bilər. İstifadəçilərə kitabxananı ən son versiyaya yeniləmək tövsiyə olunur.
FAQ2
Which versions of the DOMPurify library are affected by CVE-2026-65911?
CVE-2026-65911 affects DOMPurify up to version 3.3.3.
What is the issue described in CVE-2026-65911 regarding the `sanitize()` method?
The issue is that function predicates passed via `ADD_ATTR` or `ADD_TAGS` to `sanitize()` persist in internal state across subsequent calls.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.