---
id: CVE-2026-75838
title: >-
  DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in
  IN_PLACE sanitization where element-removal hooks fail to neutralize detached
  subtrees
summary: >-
  DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in
  IN_PLACE sanitization where element-removal hooks fail to neutralize detached
  subtrees. Attackers can supply HTML with event handlers on descendant elements
  that ex…
severity: medium
cwe:
  - CWE-79
published: '2026-08-18'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T20:02:50.260'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-75838'
references:
  - url: >-
      https://github.com/cure53/DOMPurify/security/advisories/GHSA-55q2-fjhq-7xh7
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/dompurify-before-cross-site-scripting-via-in-place-hook
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/cure53/DOMPurify/security/advisories/GHSA-55q2-fjhq-7xh7
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-75838.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-75838'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2517772'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-75838'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-75838'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71113'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67711'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67714'
  - url: 'https://access.redhat.com/errata/RHSA-2026:65118'
  - url: 'https://access.redhat.com/errata/RHSA-2026:65155'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70917'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67573'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70994'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71906'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62260'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68690'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68695'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
epss: 0.003
epssPercentile: 0.20267
ingestedAt: '2026-09-24T20:51:40.208Z'
vendor: Red Hat
product: Red Hat Ceph Storage 9
affected:
  - ansible_automation_orchestrator 2026
  - migration_toolkit_for_virtualization
  - node_healthcheck_operator
  - advanced_cluster_management_for_kubernetes 2
  - amq_broker 7
  - ansible_automation_platform 2
  - build_of_apache_camel_hawtio 4
  - build_of_apicurio_registry 3
  - build_of_podman_desktop
  - ceph_storage 6
  - ceph_storage 8
  - ceph_storage 9
  - data_grid 8
  - developer_hub
  - enterprise_linux 10
  - enterprise_linux 8
  - enterprise_linux 9
  - openshift_ai_rhoai
  - openshift_container_platform 4
  - openshift_data_foundation 4
  - openshift_dev_spaces
  - openshift_gitops
  - openshift_virtualization 4
  - ansible_automation_platform_2_6_for_rhel 9
  - advanced_cluster_security_for_kubernetes 4.10
  - advanced_cluster_security_for_kubernetes 4.11
  - ansible_automation_platform 2.1
  - ansible_automation_platform 2.2
  - hardened_images
  - openshift_dev_spaces 3.30
  - openshift_service_mesh 3.3
  - openshift_service_mesh 3.4
patched:
  - ansible_automation_platform_2_6_for_rhel 9
  - advanced_cluster_security_for_kubernetes 4.10
  - advanced_cluster_security_for_kubernetes 4.11
  - ansible_automation_platform 2.1
  - ansible_automation_platform 2.2
  - hardened_images
  - openshift_dev_spaces 3.30
  - openshift_service_mesh 3.3
  - openshift_service_mesh 3.4
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cvssSource: vendor
---

## Overview

DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detached subtrees. Attackers can supply HTML with event handlers on descendant elements that execute after sanitization completes, even though the returned root appears clean.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:71113** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71113)
- **RHSA-2026:67711** · Red Hat · fixed in: Red Hat Advanced Cluster Security for Kubernetes 4.10 · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67711)
- **RHSA-2026:67714** · Red Hat · fixed in: Red Hat Advanced Cluster Security for Kubernetes 4.11 · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67714)
- **RHSA-2026:65118** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.1 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65118)
- **RHSA-2026:65155** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.2 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65155)
- **RHSA-2026:70917** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70917)
- **RHSA-2026:67573** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67573)
- **RHSA-2026:70994** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70994)
- **RHSA-2026:71906** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-25 · [advisory](https://access.redhat.com/errata/RHSA-2026:71906)
- **RHSA-2026:62260** · Red Hat · fixed in: Red Hat OpenShift Dev Spaces 3.30 · released 2026-09-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:62260)
- **RHSA-2026:68690** · Red Hat · fixed in: Red Hat OpenShift Service Mesh 3.3 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68690)
- **Red Hat VEX** · Moderate · affected: Ansible Automation Orchestrator 2026, Migration Toolkit for Virtualization, Node HealthCheck Operator, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat AMQ Broker 7, Red Hat Ansible Automation Platform 2, … · no fix planned: Node HealthCheck Operator, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Openshift Data Foundation 4, Red Hat build of Apache Camel - HawtIO 4, … · updated 2026-09-25 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-75838.json)
