{"id":"CVE-2026-40301","aliases":["GHSA-93vf-569f-22cq"],"url":"https://o3.security/vulnerability/CVE-2026-40301","summary":"rhukster/dom-sanitizer: SVG <style> tag allows CSS injection via unfiltered url() and @import directives","details":"DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.10, DOMSanitizer::sanitize() allows <style> elements in SVG content but never inspects their text content. CSS url() references and @import rules pass through unfiltered, causing the browser to issue HTTP requests to attacker-controlled hosts when the sanitized SVG is rendered. Version 1.0.10 fixes the issue.","published":"2026-04-17T20:51:37.226Z","modified":"2026-08-12T03:51:43.258309638Z","cvss":{"score":4.7,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N"},"epss":{"score":0.00271,"percentile":0.18735,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"rhukster/dom-sanitizer","fixedVersion":"1.0.10"}],"fix":{"url":"https://github.com/rhukster/dom-sanitizer/commit/49a98046b708a4c92f754f5b0ef1720bb85142e2","label":"rhukster/dom-sanitizer@49a9804"},"references":[{"type":"WEB","url":"https://github.com/rhukster/dom-sanitizer/releases/tag/1.0.10"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40301.json"},{"type":"ADVISORY","url":"https://github.com/rhukster/dom-sanitizer/security/advisories/GHSA-93vf-569f-22cq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40301"},{"type":"FIX","url":"https://github.com/rhukster/dom-sanitizer/commit/49a98046b708a4c92f754f5b0ef1720bb85142e2"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:43.258309638Z"}}