What is CVE-2026-65912?
DOMPurify versions before 3.3.2 contain a URI validation bypass via the `ADD_ATTR` predicate in `EXTRA_ELEMENT_HANDLING.attributeCheck`, allowing attackers to craft predicates that accept specific attribute/tag combos to bypass safe URI checks. Affected users should upgrade to version 3.3.2 or later to mitigate potential DOM-based XSS risks.
Azərbaycanca: DOMPurify 3.3.2 əvvəl versiyalarda `EXTRA_ELEMENT_HANDLING.attributeCheck` vasitəsilə `ADD_ATTR` predikat funksiyası təqdim edildikdə URI validasiyasından yan keçmə zəifliyi mövcuddur. Təcavüzkar xüsusi atribut və teq kombinasiyalarını qəbul edən predikat təqdim edərək təhlükəsiz URI yoxlamasını keçə bilər. Təsirə məruz qalan sistemlərdə DOM əsaslı XSS riskini azaltmaq üçün dərhal 3.3.2 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of DOMPurify are affected by CVE-2026-65912?
All versions of DOMPurify before 3.3.2 are affected by this vulnerability.
What action should be taken to mitigate CVE-2026-65912?
You should immediately upgrade to DOMPurify version 3.3.2 or later to mitigate potential DOM-based XSS risks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.