PT-2026-63985 · Cure53 · Dompurify

·

CVE-2026-65899

·

Published

2026-07-23

·

Updated

2026-07-23

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
DOMPurify 3.0.0 before 3.4.9 does not reset the retained Trusted Types policy when clearConfig() is called, so a DOMPurify instance reused across trust boundaries stays bound to a previously supplied TRUSTED TYPES POLICY. A later caller that requests RETURN TRUSTED TYPE output receives a TrustedHTML object created by the old (potentially unsafe) policy rather than a clean default, which can lead to script execution at a Trusted Types sink. Passing TRUSTED TYPES POLICY: null on the later call also does not clear the retained policy.

Fix

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65899

Affected Products

Dompurify