Back

HIGH

DOMPurify XSS via `selectedcontent` re-clone

Published Jul 14, 2026

Description

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedcontent by default, allowing browsers to re-clone an XSS payload after sanitization so that unsanitized markup inside <selectedcontent> is returned. This issue is fixed in version 3.4.5.

Affected products

Remediation

Red Hat statement

This is a cross-site scripting (XSS) vulnerability in DOMPurify, a sanitizer for HTML, MathML, and SVG. The flaw allows a remote attacker to bypass sanitization by crafting a malicious payload that leverages the default allowance of `selectedcontent`. This can lead to browsers re-cloning the payload and executing unsanitized markup, resulting in information disclosure. User interaction is required for exploitation. * AC was raised from Low to High because exploitation requires specific browser support for the experimental <selectedcontent> HTML element, which is currently only available in Chromium 148+ and WebKit 625+. Firefox and Safari are not affected, and only the single DOMPurify version 3.4.4 is vulnerable (fixed in 3.4.5), significantly narrowing the attack surface. * Scope was lowered from Changed to Unchanged because the XSS executes within the same origin as the consuming application with no cross-domain scope change. No Red Hat product ships dompurify 3.4.4.

Red Hat mitigation

There is no direct mitigation for this flaw other than updating the DOMPurify library when upstream patches are available. As a defense-in-depth measure, Content Security Policy (CSP) headers that restrict inline script execution can help reduce the impact of XSS vulnerabilities. This issue is fixed in version 3.4.5.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jul 14, 2026
Updated Jul 16, 2026
Reserved May 19, 2026
CISA Vulnrichment
Updated Jul 16, 2026
NVD
Status Analyzed
Modified Jul 21, 2026
Red Hat
Severity Moderate
Public date Jul 14, 2026
GHSA-87XG-PXX2-7HVX