---
id: CVE-2026-49978
title: >-
  dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution
  (CVE-2026-49978)
summary: >-
  A flaw was found in DOMPurify, a tool designed to sanitize HTML, MathML, and
  SVG to prevent cross-site scripting (XSS) attacks. When performing in-place
  sanitization, DOMPurify could fail to properly process content within shadow
  DOM eleme…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'
cvssSource: vendor
cwe: CWE-79
vendor: Red Hat
product: Red Hat OpenShift AI 3.4
affected:
  - cryostat 4
  - migration_toolkit_for_virtualization
  - node_healthcheck_operator
  - amq_broker 7
  - ansible_automation_platform 2
  - build_of_apache_camel_hawtio 4
  - build_of_podman_desktop
  - ceph_storage 9
  - data_grid 8
  - openshift_ai_rhoai
  - openshift_container_platform 4
  - openshift_data_foundation 4
  - openshift_gitops
  - streams_for_apache_kafka 2
  - enterprise_linux_extensions_channel_v_10
  - advanced_cluster_security 4.9
  - advanced_cluster_security_for_kubernetes 4.10
  - advanced_cluster_security_for_kubernetes 4.11
  - ansible_automation_platform 2.2
  - container_native_virtualization 4.12
  - container_native_virtualization 4.13
  - container_native_virtualization 4.14
  - container_native_virtualization 4.15
  - container_native_virtualization 4.17
  - container_native_virtualization 4.22
  - developer_hub 1.10
  - developer_hub 1.9
  - openshift_ai 3.4
  - openshift_container_platform 4.19
  - openshift_container_platform 4.21
  - openshift_container_platform 4.22
  - openshift_container_platform 4.2
  - openshift_dev_spaces 3.30
  - openshift_service_mesh 3.3
  - openshift_service_mesh 3.4
  - build_of_apicurio_registry 3.3.1
  - streams_for_apache_kafka 3.2.1
patched:
  - enterprise_linux_extensions_channel_v_10
  - advanced_cluster_security 4.9
  - advanced_cluster_security_for_kubernetes 4.10
  - advanced_cluster_security_for_kubernetes 4.11
  - ansible_automation_platform 2.2
  - container_native_virtualization 4.12
  - container_native_virtualization 4.13
  - container_native_virtualization 4.14
  - container_native_virtualization 4.15
  - container_native_virtualization 4.17
  - container_native_virtualization 4.22
  - developer_hub 1.10
  - developer_hub 1.9
  - openshift_ai 3.4
  - openshift_container_platform 4.19
  - openshift_container_platform 4.21
  - openshift_container_platform 4.22
  - openshift_container_platform 4.2
  - openshift_dev_spaces 3.30
  - openshift_service_mesh 3.3
  - openshift_service_mesh 3.4
  - build_of_apicurio_registry 3.3.1
  - streams_for_apache_kafka 3.2.1
published: '2026-07-14'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T10:17:16+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49978.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49978.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-49978'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2500695'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-49978'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-49978'
  - url: >-
      https://github.com/cure53/DOMPurify/commit/ca30f070c360df162a3e3848e80e6fd3c9e74bff
  - url: 'https://github.com/cure53/DOMPurify/releases/tag/3.4.7'
  - url: >-
      https://github.com/cure53/DOMPurify/security/advisories/GHSA-rp9w-3fw7-7cwq
  - url: 'https://access.redhat.com/errata/RHSA-2026:57590'
  - url: 'https://access.redhat.com/errata/RHSA-2026:48872'
  - url: 'https://access.redhat.com/errata/RHSA-2026:48913'
  - url: 'https://access.redhat.com/errata/RHSA-2026:48891'
  - url: 'https://access.redhat.com/errata/RHSA-2026:42815'
  - url: 'https://access.redhat.com/errata/RHSA-2026:46623'
  - url: 'https://access.redhat.com/errata/RHSA-2026:53735'
  - url: 'https://access.redhat.com/errata/RHSA-2026:46539'
  - url: 'https://access.redhat.com/errata/RHSA-2026:53840'
  - url: 'https://access.redhat.com/errata/RHSA-2026:46558'
  - url: 'https://access.redhat.com/errata/RHSA-2026:43625'
  - url: 'https://access.redhat.com/errata/RHSA-2026:48126'
  - url: 'https://access.redhat.com/errata/RHSA-2026:49642'
  - url: 'https://access.redhat.com/errata/RHSA-2026:52768'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60520'
  - url: 'https://access.redhat.com/errata/RHSA-2026:51007'
  - url: 'https://access.redhat.com/errata/RHSA-2026:48670'
  - url: 'https://access.redhat.com/errata/RHSA-2026:48693'
  - url: 'https://access.redhat.com/errata/RHSA-2026:48676'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62260'
  - url: 'https://access.redhat.com/errata/RHSA-2026:49680'
  - url: 'https://access.redhat.com/errata/RHSA-2026:49735'
  - url: 'https://github.com/advisories/GHSA-rp9w-3fw7-7cwq'
tags:
  - csaf
  - vex
  - red-hat
  - ghsa
  - npm
epss: 0.00404
epssPercentile: 0.32062
aliases:
  - GHSA-rp9w-3fw7-7cwq
ecosystem: npm
ingestedAt: '2026-07-07T15:41:58.704Z'
---

## Overview

A flaw was found in DOMPurify, a tool designed to sanitize HTML, MathML, and SVG to prevent cross-site scripting (XSS) attacks. When performing in-place sanitization, DOMPurify could fail to properly process content within shadow DOM elements attached to a `<template>.content`. This oversight allows an attacker to embed malicious code, such as JavaScript, which could then execute when the sanitized template is used by an application, potentially leading to unauthorized actions or information disclosure.

## Vendor advisories

- **RHSA-2026:57590** · Red Hat · fixed in: Red Hat Enterprise Linux Extensions Channel (v. 10) · released 2026-08-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:57590)
- **RHSA-2026:48872** · Red Hat · fixed in: Red Hat Advanced Cluster Security 4.9 · released 2026-07-30 · [advisory](https://access.redhat.com/errata/RHSA-2026:48872)
- **RHSA-2026:48913** · Red Hat · fixed in: Red Hat Advanced Cluster Security for Kubernetes 4.10 · released 2026-07-30 · [advisory](https://access.redhat.com/errata/RHSA-2026:48913)
- **RHSA-2026:48891** · Red Hat · fixed in: Red Hat Advanced Cluster Security for Kubernetes 4.11 · released 2026-07-30 · [advisory](https://access.redhat.com/errata/RHSA-2026:48891)
- **RHSA-2026:42815** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.2 · released 2026-07-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:42815)
- **RHSA-2026:46623** · Red Hat · fixed in: Red Hat Container Native Virtualization 4.12 · released 2026-07-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:46623)
- **RHSA-2026:53735** · Red Hat · fixed in: Red Hat Container Native Virtualization 4.13 · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53735)
- **RHSA-2026:46539** · Red Hat · fixed in: Red Hat Container Native Virtualization 4.14 · released 2026-07-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:46539)
- **RHSA-2026:53840** · Red Hat · fixed in: Red Hat Container Native Virtualization 4.15 · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53840)
- **RHSA-2026:46558** · Red Hat · fixed in: Red Hat Container Native Virtualization 4.17 · released 2026-07-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:46558)
- **RHSA-2026:43625** · Red Hat · fixed in: Red Hat Container Native Virtualization 4.22 · released 2026-07-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:43625)
- **Red Hat VEX** · Important · affected: Cryostat 4, Migration Toolkit for Virtualization, Node HealthCheck Operator, Red Hat AMQ Broker 7, Red Hat Ansible Automation Platform 2, Red Hat build of Apache Camel - HawtIO 4, … · no fix planned: Red Hat Ceph Storage 9, Red Hat Openshift Data Foundation 4, Cryostat 4, Migration Toolkit for Virtualization, … · updated 2026-09-08 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49978.json)

**dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution** — rated Important by Red Hat. Released 2026-07-14, updated 2026-09-08.

Affected:

- Cryostat 4
- Migration Toolkit for Virtualization
- Node HealthCheck Operator
- Red Hat AMQ Broker 7
- Red Hat Ansible Automation Platform 2
- Red Hat build of Apache Camel - HawtIO 4
- Red Hat Build of Podman Desktop
- Red Hat Ceph Storage 9
- Red Hat Data Grid 8
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat Openshift Data Foundation 4
- Red Hat OpenShift GitOps
- streams for Apache Kafka 2

Fixed:

- Red Hat Enterprise Linux Extensions Channel (v. 10)
- Red Hat Advanced Cluster Security 4.9
- Red Hat Advanced Cluster Security for Kubernetes 4.10
- Red Hat Advanced Cluster Security for Kubernetes 4.11
- Red Hat Ansible Automation Platform 2.2
- Red Hat Container Native Virtualization 4.12
- Red Hat Container Native Virtualization 4.13
- Red Hat Container Native Virtualization 4.14
- Red Hat Container Native Virtualization 4.15
- Red Hat Container Native Virtualization 4.17
- Red Hat Container Native Virtualization 4.22
- Red Hat Developer Hub 1.10
- Red Hat Developer Hub 1.9
- Red Hat OpenShift AI 3.4
- Red Hat OpenShift Container Platform 4.19
- Red Hat OpenShift Container Platform 4.21
- Red Hat OpenShift Container Platform 4.22
- Red Hat OpenShift Container Platform 4.2
- Red Hat OpenShift Dev Spaces 3.30
- Red Hat OpenShift Service Mesh 3.3
- Red Hat OpenShift Service Mesh 3.4
- Red Hat build of Apicurio Registry 3.3.1
- Streams for Apache Kafka 3.2.1

No fix planned:

- Red Hat Ceph Storage 9
- Red Hat Openshift Data Foundation 4
- Cryostat 4
- Migration Toolkit for Virtualization
- Node HealthCheck Operator
- Red Hat AMQ Broker 7
- Red Hat Ansible Automation Platform 2
- Red Hat build of Apache Camel - HawtIO 4
- Red Hat Build of Podman Desktop
- Red Hat Data Grid 8
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift GitOps
- streams for Apache Kafka 2

Not affected:

- Red Hat Advanced Cluster Security 4.9
- Red Hat Advanced Cluster Security for Kubernetes 4.10
- Red Hat Advanced Cluster Security for Kubernetes 4.11
- Red Hat Developer Hub 1.10
- Red Hat Developer Hub 1.9
- Red Hat OpenShift AI 3.4
- Red Hat OpenShift Container Platform 4.19
- Red Hat OpenShift Container Platform 4.21
- Red Hat OpenShift Container Platform 4.22
- Red Hat OpenShift Container Platform 4.2

## Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:57590
If you are using an earlier version of RHACS, you are advised to
upgrade to the version of RHACS mentioned in the synopsis and release
notes in order to take advantage of the enhancements, bug fixes, and/or
security patches in the release. https://access.redhat.com/errata/RHSA-2026:48872
If you are using an earlier version of RHACS, you are advised to
upgrade to the version of RHACS mentioned in the synopsis and release
notes in order to take advantage of the enhancements, bug fixes, and/or
security patches in the release. https://access.redhat.com/errata/RHSA-2026:48913

## Package advisory (CVE-2026-49978)

Affected packages:

- `dompurify <= 3.4.6`

Patched in:

- `dompurify 3.4.7`

Source: https://github.com/advisories/GHSA-rp9w-3fw7-7cwq
