{"id":"CVE-2026-65899","aliases":["GHSA-vxr8-fq34-vvx9"],"url":"https://o3.security/vulnerability/CVE-2026-65899","summary":"DOMPurify before 3.4.9 Trusted Types Policy State Contamination","details":"DOMPurify 3.0.0 before 3.4.9 does not reset the retained Trusted Types policy when clearConfig() is called, so a DOMPurify instance reused across trust boundaries stays bound to a previously supplied TRUSTED_TYPES_POLICY. A later caller that requests RETURN_TRUSTED_TYPE output receives a TrustedHTML object created by the old (potentially unsafe) policy rather than a clean default, which can lead to script execution at a Trusted Types sink. Passing TRUSTED_TYPES_POLICY: null on the later call also does not clear the retained policy.","published":"2026-07-23T13:16:18.389Z","modified":"2026-08-12T03:51:25.428150057Z","cvss":null,"epss":{"score":0.00266,"percentile":0.18464,"asOf":"2026-09-01"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"dompurify","fixedVersion":"3.4.9"}],"fix":{"url":"https://github.com/cure53/DOMPurify/commit/825e617753ac1169306a542d3174a77f717a0cf6","label":"cure53/DOMPurify@825e617"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/65xxx/CVE-2026-65899.json"},{"type":"ADVISORY","url":"https://github.com/cure53/DOMPurify/security/advisories/GHSA-vxr8-fq34-vvx9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-65899"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/dompurify-before-trusted-types-policy-state-contamination"},{"type":"FIX","url":"https://github.com/cure53/DOMPurify/commit/825e617753ac1169306a542d3174a77f717a0cf6"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:25.428150057Z"}}