---
id: CVE-2026-65899
title: >-
  DOMPurify 3.0.0 before 3.4.9 does not reset the retained Trusted Types policy
  when clearConfig() is called, so a DOMPurify instance reused across trust
  boundaries stays bound to a previously supplied TRUSTED_TYPES_POLICY
summary: >-
  DOMPurify 3.0.0 before 3.4.9 does not reset the retained Trusted Types policy
  when clearConfig() is called, so a DOMPurify instance reused across trust
  boundaries stays bound to a previously supplied TRUSTED_TYPES_POLICY. A later
  caller …
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-693
vendor: cure53
product: dompurify
affected:
  - 'dompurify >= 3.0.0, < 3.4.9'
patched:
  - dompurify 3.4.9
published: '2026-07-23'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:29.863'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-65899'
references:
  - url: >-
      https://github.com/cure53/DOMPurify/commit/825e617753ac1169306a542d3174a77f717a0cf6
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/cure53/DOMPurify/security/advisories/GHSA-vxr8-fq34-vvx9
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/dompurify-before-trusted-types-policy-state-contamination
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-07-27T16:15:29.603133Z'
epss: 0.00413
epssPercentile: 0.33448
ingestedAt: '2026-10-08T16:52:14.707Z'
---

## Overview

DOMPurify 3.0.0 before 3.4.9 does not reset the retained Trusted Types policy when clearConfig() is called, so a DOMPurify instance reused across trust boundaries stays bound to a previously supplied TRUSTED_TYPES_POLICY. A later caller that requests RETURN_TRUSTED_TYPE output receives a TrustedHTML object created by the old (potentially unsafe) policy rather than a clean default, which can lead to script execution at a Trusted Types sink. Passing TRUSTED_TYPES_POLICY: null on the later call also does not clear the retained policy.

## Affected

- `dompurify >= 3.0.0, < 3.4.9`

## Remediation

Upgrade past the affected range:

- `dompurify 3.4.9`
