Information on source package node-dompurify

Available versions

ReleaseVersion
bookworm2.4.1+dfsg+~2.4.0-2+deb12u1
bookworm (security)2.4.1+dfsg+~2.4.0-2
trixie3.1.7+dfsg+~3.0.5-2
forky3.4.12+dfsg-1
sid3.4.12+dfsg-1

Open issues

BugbookwormtrixieforkysidDescription
CVE-2026-66010vulnerablevulnerablefixedfixedDOMPurify before 3.4.12 fails to execute afterSanitizeElements hook fo ...
CVE-2026-65914vulnerablevulnerablefixedfixedDOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sani ...
CVE-2026-65913vulnerablevulnerablefixedfixedDOMPurify before 3.3.2 contains a prototype pollution vulnerability in ...
CVE-2026-65912vulnerablevulnerablefixedfixedDOMPurify before 3.3.2 contains a URI validation bypass vulnerability ...
CVE-2026-65911vulnerablevulnerablefixedfixedIn DOMPurify through 3.3.3, function predicates supplied via ADD_ATTR ...
CVE-2026-65904vulnerablevulnerablefixedfixedDOMPurify through 3.3.3 fails to sanitize DOM elements passed via IN_P ...
CVE-2026-65903vulnerablevulnerablefixedfixedDOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function ...
CVE-2026-65902vulnerablevulnerablefixedfixedDOMPurify before 3.4.7 (affected versions <= 3.4.5) passes direct refe ...
CVE-2026-65901vulnerablevulnerablefixedfixedDOMPurify through 3.4.6 contains a cross-site scripting vulnerability ...
CVE-2026-65900vulnerablevulnerablefixedfixedDOMPurify versions >=3.0.0 and before 3.4.8, when configured with SAFE ...
CVE-2026-65899vulnerablevulnerablefixedfixedDOMPurify 3.0.0 before 3.4.9 does not reset the retained Trusted Types ...
CVE-2026-65898vulnerablevulnerablefixedfixedDOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when ...
CVE-2026-49978vulnerablevulnerablefixedfixedDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathM ...
CVE-2026-49459vulnerablevulnerablefixedfixedDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathM ...
CVE-2026-49458vulnerablevulnerablefixedfixedDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathM ...
CVE-2026-47423vulnerablevulnerablefixedfixedDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathM ...
CVE-2026-41240vulnerablevulnerablefixedfixedDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathM ...
CVE-2026-41239vulnerablevulnerablefixedfixedDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathM ...
CVE-2026-41238vulnerablevulnerablefixedfixedDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathM ...
CVE-2026-0540vulnerablevulnerablefixedfixedDOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit ...
CVE-2025-26791vulnerable (no DSA)fixedfixedfixedDOMPurify before 3.2.4 has an incorrect template literal regular expre ...
CVE-2025-15599vulnerablevulnerablefixedfixedDOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross- ...

Open unimportant issues

BugbookwormtrixieforkysidDescription
CVE-2025-48050vulnerablevulnerablefixedfixedIn DOMPurify through 3.2.5 before 6bc6d60, scripts/server.js does not ...

Resolved issues

BugDescription
CVE-2024-48910DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for H ...
CVE-2024-47875DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for H ...
CVE-2024-45801DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for H ...

Security announcements

DSA / DLADescription
DSA-5790-1node-dompurify - security update

Search for package or bug name: Reporting problems