Security Advisory

CVE-2026-65914

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-23 13:16:24
Last updated 2026-07-23 13:57:53
Assigner VulnCheck
CVSS score 5.3
State PUBLISHED

Description

DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing contexts using innerHTML with wrappers like script, xmp, iframe, noembed, noframes, or noscript. Attackers can craft payloads with closing sequences that break out of the wrapper context during reparsing, reactivating dangerous markup with event handlers to execute JavaScript.