DOMPurify XSS via `selectedcontent` re-clone
Published Jul 14, 2026
8.2
HIGHCVSS 3.1
EPSS 0.41%
Description
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedcontent by default, allowing browsers to re-clone an XSS payload after sanitization so that unsanitized markup inside <selectedcontent> is returned. This issue is fixed in version 3.4.5.
Affected products
-
- Version >= 3.4.4, < 3.4.5StatusaffectedConstraints-
- Version
No data.
Red Hat Hardened Images
ruff-main-0.15.11-1.hum1
Fixed · RHSA-2026:10999
Cryostat 4
dompurify
Not affected
Migration Toolkit for Virtualization
migration-toolkit-virtualization/mtv-console-plugin-rhel9
Not affected
Multicluster Engine for Kubernetes
multicluster-engine/console-mce-rhel9
Not affected
Node HealthCheck Operator
workload-availability/node-healthcheck-must-gather-rhel9
Not affected
Node HealthCheck Operator
workload-availability/node-healthcheck-operator-bundle
Not affected
Node HealthCheck Operator
workload-availability/node-healthcheck-rhel9-operator
Not affected
OpenShift Lightspeed
openshift-lightspeed/lightspeed-agentic-console-rhel9
Not affected
OpenShift Lightspeed
openshift-lightspeed/lightspeed-console-plugin-419-rhel9
Not affected
OpenShift Lightspeed
openshift-lightspeed/lightspeed-console-plugin-pf5-rhel9
Not affected
OpenShift Lightspeed
openshift-lightspeed/lightspeed-console-plugin-rhel9
Not affected
OpenShift Service Mesh 3
openshift-service-mesh/kiali-ossmc-rhel9
Not affected
OpenShift Service Mesh 3
openshift-service-mesh/kiali-rhel9
Not affected
Red Hat AMQ Broker 7
dompurify
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/console-rhel9
Not affected
Red Hat Advanced Cluster Security 4
advanced-cluster-security/rhacs-main-rhel8
Not affected
Red Hat Advanced Cluster Security 4
advanced-cluster-security/rhacs-main-rhel9
Not affected
Red Hat Ansible Automation Platform 2
ansible-automation-platform-26/gateway-rhel9
Not affected
Red Hat Ansible Automation Platform 2
ansible-automation-platform-27/gateway-rhel9
Not affected
Red Hat Build of Podman Desktop
rh-podman-desktop.git
Not affected
Red Hat Ceph Storage 9
rhceph/alloy-rhel10
Fix deferred
Red Hat Data Grid 8
dompurify
Not affected
Red Hat Developer Hub
rhdh/rhdh-hub-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-dashboard-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-mod-arch-automl-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-mod-arch-autorag-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-mod-arch-eval-hub-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-mod-arch-gen-ai-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-mod-arch-maas-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-mod-arch-mlflow-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-mod-arch-model-registry-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-agent-installer-ui-rhel9
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-console
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-console-rhel9
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-monitoring-plugin-rhel8
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-monitoring-plugin-rhel9
Not affected
Red Hat OpenShift Dev Spaces
devspaces/code-rhel9
Not affected
Red Hat OpenShift Dev Spaces
devspaces/openvsx-rhel9
Not affected
Red Hat OpenShift GitOps
openshift-gitops-1/argocd-rhel8
Not affected
Red Hat OpenShift GitOps
openshift-gitops-1/argocd-rhel9
Not affected
Red Hat OpenShift Virtualization 4
container-native-virtualization/kubevirt-console-plugin
Not affected
Red Hat OpenShift Virtualization 4
container-native-virtualization/kubevirt-console-plugin-rhel9
Not affected
Red Hat Openshift Data Foundation 4
odf4/ocs-client-console-rhel9
Not affected
Red Hat Openshift Data Foundation 4
odf4/odf-console-rhel9
Affected
Red Hat Openshift Data Foundation 4
odf4/odf-multicluster-console-rhel9
Not affected
Red Hat build of Apache Camel - HawtIO 4
dompurify
Not affected
Red Hat build of Apache Camel for Spring Boot 4
dompurify
Not affected
Self-service automation portal 2
ansible-automation-platform/automation-portal
Not affected
streams for Apache Kafka 2
dompurify
Not affected
streams for Apache Kafka 3
dompurify
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | ruff-main-0.15.11-1.hum1 | Fixed | RHSA-2026:10999 |
| Cryostat 4 | dompurify | Not affected | n/a |
| Migration Toolkit for Virtualization | migration-toolkit-virtualization/mtv-console-plugin-rhel9 | Not affected | n/a |
| Multicluster Engine for Kubernetes | multicluster-engine/console-mce-rhel9 | Not affected | n/a |
| Node HealthCheck Operator | workload-availability/node-healthcheck-must-gather-rhel9 | Not affected | n/a |
| Node HealthCheck Operator | workload-availability/node-healthcheck-operator-bundle | Not affected | n/a |
| Node HealthCheck Operator | workload-availability/node-healthcheck-rhel9-operator | Not affected | n/a |
| OpenShift Lightspeed | openshift-lightspeed/lightspeed-agentic-console-rhel9 | Not affected | n/a |
| OpenShift Lightspeed | openshift-lightspeed/lightspeed-console-plugin-419-rhel9 | Not affected | n/a |
| OpenShift Lightspeed | openshift-lightspeed/lightspeed-console-plugin-pf5-rhel9 | Not affected | n/a |
| OpenShift Lightspeed | openshift-lightspeed/lightspeed-console-plugin-rhel9 | Not affected | n/a |
| OpenShift Service Mesh 3 | openshift-service-mesh/kiali-ossmc-rhel9 | Not affected | n/a |
| OpenShift Service Mesh 3 | openshift-service-mesh/kiali-rhel9 | Not affected | n/a |
| Red Hat AMQ Broker 7 | dompurify | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/console-rhel9 | Not affected | n/a |
| Red Hat Advanced Cluster Security 4 | advanced-cluster-security/rhacs-main-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Security 4 | advanced-cluster-security/rhacs-main-rhel9 | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-26/gateway-rhel9 | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-27/gateway-rhel9 | Not affected | n/a |
| Red Hat Build of Podman Desktop | rh-podman-desktop.git | Not affected | n/a |
| Red Hat Ceph Storage 9 | rhceph/alloy-rhel10 | Fix deferred | n/a |
| Red Hat Data Grid 8 | dompurify | Not affected | n/a |
| Red Hat Developer Hub | rhdh/rhdh-hub-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-dashboard-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mod-arch-automl-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mod-arch-autorag-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mod-arch-eval-hub-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mod-arch-gen-ai-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mod-arch-maas-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mod-arch-mlflow-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mod-arch-model-registry-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-agent-installer-ui-rhel9 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-console | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-console-rhel9 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-monitoring-plugin-rhel8 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-monitoring-plugin-rhel9 | Not affected | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/code-rhel9 | Not affected | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/openvsx-rhel9 | Not affected | n/a |
| Red Hat OpenShift GitOps | openshift-gitops-1/argocd-rhel8 | Not affected | n/a |
| Red Hat OpenShift GitOps | openshift-gitops-1/argocd-rhel9 | Not affected | n/a |
| Red Hat OpenShift Virtualization 4 | container-native-virtualization/kubevirt-console-plugin | Not affected | n/a |
| Red Hat OpenShift Virtualization 4 | container-native-virtualization/kubevirt-console-plugin-rhel9 | Not affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/ocs-client-console-rhel9 | Not affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/odf-console-rhel9 | Affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/odf-multicluster-console-rhel9 | Not affected | n/a |
| Red Hat build of Apache Camel - HawtIO 4 | dompurify | Not affected | n/a |
| Red Hat build of Apache Camel for Spring Boot 4 | dompurify | Not affected | n/a |
| Self-service automation portal 2 | ansible-automation-platform/automation-portal | Not affected | n/a |
| streams for Apache Kafka 2 | dompurify | Not affected | n/a |
| streams for Apache Kafka 3 | dompurify | Not affected | n/a |
dompurify
npm
Introduced 3.4.4 Fixed 3.4.5
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | dompurify | 3.4.4 | 3.4.5 |
Remediation
Red Hat statement
This is a cross-site scripting (XSS) vulnerability in DOMPurify, a sanitizer for HTML, MathML, and SVG. The flaw allows a remote attacker to bypass sanitization by crafting a malicious payload that leverages the default allowance of `selectedcontent`. This can lead to browsers re-cloning the payload and executing unsanitized markup, resulting in information disclosure. User interaction is required for exploitation. * AC was raised from Low to High because exploitation requires specific browser support for the experimental <selectedcontent> HTML element, which is currently only available in Chromium 148+ and WebKit 625+. Firefox and Safari are not affected, and only the single DOMPurify version 3.4.4 is vulnerable (fixed in 3.4.5), significantly narrowing the attack surface. * Scope was lowered from Changed to Unchanged because the XSS executes within the same origin as the consuming application with no cross-domain scope change. No Red Hat product ships dompurify 3.4.4.
Red Hat mitigation
There is no direct mitigation for this flaw other than updating the DOMPurify library when upstream patches are available. As a defense-in-depth measure, Content Security Policy (CSP) headers that restrict inline script execution can help reduce the impact of XSS vulnerabilities. This issue is fixed in version 3.4.5.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Jul 16, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
Jun–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.41% (0.00410) | 32.90th | v5 (v2026.06.15) |
| Jul 15, 2026 | 0.28% (0.00278) | 19.69th | v5 (v2026.06.15) |
| Jun 12, 2026 | 0.03% (0.00035) | 10.92th | v4 (v2025.03.14) |
References (8)
- https://access.redhat.com/security/cve/CVE-2026-47423 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2500564 Issue Tracking
- https://github.com/advisories/GHSA-87xg-pxx2-7hvx Advisory
- https://github.com/cure53/DOMPurify/commit/011b0c78f2a0f57ee54f5fcccb697a46ca6e63ea x_refsource_MISCPatch
- https://github.com/cure53/DOMPurify/releases/tag/3.4.5 x_refsource_MISCRelease Notes
- https://github.com/cure53/DOMPurify/security/advisories/GHSA-87xg-pxx2-7hvx exploitx_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-47423
- https://www.cve.org/CVERecord?id=CVE-2026-47423
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-47423 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2500564 | Issue Tracking | |
| https://github.com/advisories/GHSA-87xg-pxx2-7hvx | Advisory | |
| https://github.com/cure53/DOMPurify/commit/011b0c78f2a0f57ee54f5fcccb697a46ca6e63ea | x_refsource_MISCPatch | |
| https://github.com/cure53/DOMPurify/releases/tag/3.4.5 | x_refsource_MISCRelease Notes | |
| https://github.com/cure53/DOMPurify/security/advisories/GHSA-87xg-pxx2-7hvx | exploitx_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-47423 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-47423 |
Change history (0)
No recorded changes yet.