CVE-2026-65902
Published Jul 23, 2026DOMPurify before 3.4.7 (affected versions <= 3.4.5) passes direct references to the module-level DEFAULT_ALLOWED_TAGS and DEFAULT_ALLOWED_ATTR sets to the uponSanitizeElement and…
- evidence mentions
- 3
- Buzz score
- 20.4