CVE-2026-75838

NameCVE-2026-75838
DescriptionDOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detached subtrees. Attackers can supply HTML with event handlers on descendant elements that execute after sanitization completes, even though the returned root appears clean.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
node-dompurify (PTS)bookworm2.4.1+dfsg+~2.4.0-2+deb12u1vulnerable
bookworm (security)2.4.1+dfsg+~2.4.0-2vulnerable
trixie3.1.7+dfsg+~3.0.5-2vulnerable
forky3.4.13+dfsg-1fixed
sid3.4.13+dfsg-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
node-dompurifysource(unstable)3.4.13+dfsg-1

Notes

https://github.com/cure53/DOMPurify/security/advisories/GHSA-55q2-fjhq-7xh7

Search for package or bug name: Reporting problems