{"id":"CVE-2026-65903","aliases":["GHSA-39q2-94rc-95cp"],"url":"https://o3.security/vulnerability/CVE-2026-65903","summary":"DOMPurify before 3.4.0 ADD_TAGS Function Bypasses FORBID_TAGS","details":"DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function where short-circuit evaluation allows forbidden tags to bypass FORBID_TAGS restrictions. Attackers can craft input containing tags listed in FORBID_TAGS that are also added via ADD_TAGS function, causing them to be retained in sanitized output.","published":"2026-07-23T13:16:21.187Z","modified":"2026-08-12T03:51:33.184694268Z","cvss":null,"epss":{"score":0.002,"percentile":0.10081,"asOf":"2026-08-12"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"dompurify","fixedVersion":"3.4.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/65xxx/CVE-2026-65903.json"},{"type":"ADVISORY","url":"https://github.com/cure53/DOMPurify/security/advisories/GHSA-39q2-94rc-95cp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-65903"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/dompurify-before-add-tags-function-bypasses-forbid-tags"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:33.184694268Z"}}