HIGH

CVE-2026-65898

CVSS v3

7.2

HIGH

EPSS Score

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute hook, allowing the hook to permanently mutate the shared allowlist. Attackers can register a hook that conditionally allows dangerous attributes like onerror for trusted elements, then submit untrusted content that inherits the polluted allowlist and executes event handlers as stored XSS.

Technical details

CVSS v3 Vector
3.1
Published
7/23/2026
Last Modified
7/23/2026

Frequently asked questions

What is CVE-2026-65898?

DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute hook, allowing the hook to permanently mutate the shared allowlist. Attackers can register a hook that conditionally allows dangerous attributes like onerror for trusted elements, then submit untrusted content that inherits the polluted allowlist and executes event handlers as stored XSS.

Is CVE-2026-65898 actively exploited?

Active exploitation of CVE-2026-65898 has not been confirmed. The EPSS score is N/A%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-65898?

CVE-2026-65898 has a CVSS v3 base score of 7.2 (HIGH severity), with vector string 3.1.

Is CVE-2026-65898 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.