Search
Find a vulnerability
Search criteria
8 vulnerabilities by rhukster
CVE-2026-103687 (GCVE-0-2026-103687)
Vulnerability from nvd – Published: 2026-10-01 14:30 – Updated: 2026-10-01 15:07 X_Open Source
VLAI
EPSS
VEX
Title
rhukster dom-sanitizer SVG Sanitization DOMSanitizer.php url incomplete blacklist
Summary
A vulnerability has been found in rhukster dom-sanitizer up to 1.0.15. The affected element is the function url of the file src/DOMSanitizer.php of the component SVG Sanitization. Such manipulation leads to incomplete blacklist. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.16 is sufficient to fix this issue. The name of the patch is 139c46c3d7c9bc81542b7b5a58d5cde5d0e0195a. Upgrading the affected component is recommended.
Severity
SSVC
Exploitation: poc
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 15:06 UTC
Assigner
References
8 references
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/412551 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/412551/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-103687 | third-party-advisory |
| https://vuldb.com/submit/958345 | third-party-advisory |
| https://github.com/rhukster/dom-sanitizer/securit… | exploit |
| https://github.com/rhukster/dom-sanitizer/commit/… | patch |
| https://github.com/rhukster/dom-sanitizer/release… | patch |
| https://github.com/rhukster/dom-sanitizer/ | product |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| rhukster | dom-sanitizer |
Affected:
1.0.0
Affected: 1.0.1 Affected: 1.0.2 Affected: 1.0.3 Affected: 1.0.4 Affected: 1.0.5 Affected: 1.0.6 Affected: 1.0.7 Affected: 1.0.8 Affected: 1.0.9 Affected: 1.0.10 Affected: 1.0.11 Affected: 1.0.12 Affected: 1.0.13 Affected: 1.0.14 Affected: 1.0.15 Unaffected: 1.0.16 cpe:2.3:a:rhukster:dom-sanitizer:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103687",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:06:52.309985Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T15:07:06.705Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:rhukster:dom-sanitizer:*:*:*:*:*:*:*:*"
],
"modules": [
"SVG Sanitization"
],
"product": "dom-sanitizer",
"vendor": "rhukster",
"versions": [
{
"status": "affected",
"version": "1.0.0"
},
{
"status": "affected",
"version": "1.0.1"
},
{
"status": "affected",
"version": "1.0.2"
},
{
"status": "affected",
"version": "1.0.3"
},
{
"status": "affected",
"version": "1.0.4"
},
{
"status": "affected",
"version": "1.0.5"
},
{
"status": "affected",
"version": "1.0.6"
},
{
"status": "affected",
"version": "1.0.7"
},
{
"status": "affected",
"version": "1.0.8"
},
{
"status": "affected",
"version": "1.0.9"
},
{
"status": "affected",
"version": "1.0.10"
},
{
"status": "affected",
"version": "1.0.11"
},
{
"status": "affected",
"version": "1.0.12"
},
{
"status": "affected",
"version": "1.0.13"
},
{
"status": "affected",
"version": "1.0.14"
},
{
"status": "affected",
"version": "1.0.15"
},
{
"status": "unaffected",
"version": "1.0.16"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "0xMo-Error (VulDB User)"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability has been found in rhukster dom-sanitizer up to 1.0.15. The affected element is the function url of the file src/DOMSanitizer.php of the component SVG Sanitization. Such manipulation leads to incomplete blacklist. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.16 is sufficient to fix this issue. The name of the patch is 139c46c3d7c9bc81542b7b5a58d5cde5d0e0195a. Upgrading the affected component is recommended."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-184",
"description": "Incomplete Blacklist",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-183",
"description": "Permissive List of Allowed Inputs",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T14:30:12.624Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-412551 | rhukster dom-sanitizer SVG Sanitization DOMSanitizer.php url incomplete blacklist",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/412551"
},
{
"name": "VDB-412551 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/412551/cti"
},
{
"name": "CVE-2026-103687 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-103687"
},
{
"name": "Submit #958345 | rhukster dom-sanitizer \u003c= 1.0.15 Improper Input Validation",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/958345"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/rhukster/dom-sanitizer/security/advisories/GHSA-cjfg-j8jp-5xvc"
},
{
"tags": [
"patch"
],
"url": "https://github.com/rhukster/dom-sanitizer/commit/139c46c3d7c9bc81542b7b5a58d5cde5d0e0195a"
},
{
"tags": [
"patch"
],
"url": "https://github.com/rhukster/dom-sanitizer/releases/tag/1.0.16"
},
{
"tags": [
"product"
],
"url": "https://github.com/rhukster/dom-sanitizer/"
}
],
"tags": [
"x_open-source"
],
"timeline": [
{
"lang": "en",
"time": "2026-10-01T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-10-01T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-10-01T11:36:45.000Z",
"value": "VulDB entry last update"
}
],
"title": "rhukster dom-sanitizer SVG Sanitization DOMSanitizer.php url incomplete blacklist",
"x_generator": [
"VulDB PVTS v202610"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-103687",
"datePublished": "2026-10-01T14:30:12.624Z",
"dateReserved": "2026-10-01T09:31:35.763Z",
"dateUpdated": "2026-10-01T15:07:06.705Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103686 (GCVE-0-2026-103686)
Vulnerability from nvd – Published: 2026-10-01 13:45 – Updated: 2026-10-01 13:45 X_Open Source
VLAI
EPSS
VEX
Title
rhukster dom-sanitizer URL Validation DOMSanitizer.php isDangerousUrl cross site scripting
Summary
A flaw has been found in rhukster dom-sanitizer up to 1.0.15. Impacted is the function DOMSanitizer::isDangerousUrl of the file src/DOMSanitizer.php of the component URL Validation. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be used. Upgrading to version 1.0.16 is recommended to address this issue. Patch name: 4623b565d060bc02ca5a07d8c8241fe28e2edfda. It is suggested to upgrade the affected component.
Severity
Assigner
References
8 references
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/412550 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/412550/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-103686 | third-party-advisory |
| https://vuldb.com/submit/958312 | third-party-advisory |
| https://github.com/rhukster/dom-sanitizer/securit… | exploit |
| https://github.com/rhukster/dom-sanitizer/commit/… | patch |
| https://github.com/rhukster/dom-sanitizer/release… | patch |
| https://github.com/rhukster/dom-sanitizer/ | product |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| rhukster | dom-sanitizer |
Affected:
1.0.0
Affected: 1.0.1 Affected: 1.0.2 Affected: 1.0.3 Affected: 1.0.4 Affected: 1.0.5 Affected: 1.0.6 Affected: 1.0.7 Affected: 1.0.8 Affected: 1.0.9 Affected: 1.0.10 Affected: 1.0.11 Affected: 1.0.12 Affected: 1.0.13 Affected: 1.0.14 Affected: 1.0.15 Unaffected: 1.0.16 cpe:2.3:a:rhukster:dom-sanitizer:*:*:*:*:*:*:*:* |
{
"containers": {
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:rhukster:dom-sanitizer:*:*:*:*:*:*:*:*"
],
"modules": [
"URL Validation"
],
"product": "dom-sanitizer",
"vendor": "rhukster",
"versions": [
{
"status": "affected",
"version": "1.0.0"
},
{
"status": "affected",
"version": "1.0.1"
},
{
"status": "affected",
"version": "1.0.2"
},
{
"status": "affected",
"version": "1.0.3"
},
{
"status": "affected",
"version": "1.0.4"
},
{
"status": "affected",
"version": "1.0.5"
},
{
"status": "affected",
"version": "1.0.6"
},
{
"status": "affected",
"version": "1.0.7"
},
{
"status": "affected",
"version": "1.0.8"
},
{
"status": "affected",
"version": "1.0.9"
},
{
"status": "affected",
"version": "1.0.10"
},
{
"status": "affected",
"version": "1.0.11"
},
{
"status": "affected",
"version": "1.0.12"
},
{
"status": "affected",
"version": "1.0.13"
},
{
"status": "affected",
"version": "1.0.14"
},
{
"status": "affected",
"version": "1.0.15"
},
{
"status": "unaffected",
"version": "1.0.16"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "0xMo-Error (VulDB User)"
}
],
"descriptions": [
{
"lang": "en",
"value": "A flaw has been found in rhukster dom-sanitizer up to 1.0.15. Impacted is the function DOMSanitizer::isDangerousUrl of the file src/DOMSanitizer.php of the component URL Validation. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be used. Upgrading to version 1.0.16 is recommended to address this issue. Patch name: 4623b565d060bc02ca5a07d8c8241fe28e2edfda. It is suggested to upgrade the affected component."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 3.5,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 3.5,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 4,
"vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:OF/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Cross Site Scripting",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-94",
"description": "Code Injection",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T13:45:12.259Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-412550 | rhukster dom-sanitizer URL Validation DOMSanitizer.php isDangerousUrl cross site scripting",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/412550"
},
{
"name": "VDB-412550 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/412550/cti"
},
{
"name": "CVE-2026-103686 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-103686"
},
{
"name": "Submit #958312 | rhukster dom-sanitizer \u003c= 1.0.15 Improper Input Validation",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/958312"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/rhukster/dom-sanitizer/security/advisories/GHSA-mrpv-6x26-mf6c"
},
{
"tags": [
"patch"
],
"url": "https://github.com/rhukster/dom-sanitizer/commit/4623b565d060bc02ca5a07d8c8241fe28e2edfda"
},
{
"tags": [
"patch"
],
"url": "https://github.com/rhukster/dom-sanitizer/releases/tag/1.0.16"
},
{
"tags": [
"product"
],
"url": "https://github.com/rhukster/dom-sanitizer/"
}
],
"tags": [
"x_open-source"
],
"timeline": [
{
"lang": "en",
"time": "2026-10-01T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-10-01T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-10-01T11:36:41.000Z",
"value": "VulDB entry last update"
}
],
"title": "rhukster dom-sanitizer URL Validation DOMSanitizer.php isDangerousUrl cross site scripting",
"x_generator": [
"VulDB PVTS v202610"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-103686",
"datePublished": "2026-10-01T13:45:12.259Z",
"dateReserved": "2026-10-01T09:31:30.531Z",
"dateUpdated": "2026-10-01T13:45:12.259Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100370 (GCVE-0-2026-100370)
Vulnerability from nvd – Published: 2026-09-28 20:07 – Updated: 2026-09-28 20:40
VLAI
EPSS
VEX
Title
DOMSanitizer - Incomplete data: URL Sanitization in DOMSanitizer::isDangerousUrl() Allows Base64-Encoded Payloads to Bypass href and xlink:href Validation
Summary
DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.15, the isDangerousUrl() method is responsible for rejecting dangerous URL values in the href and xlink:href attributes. The weakness is that "javascript:" is rejected as a scheme, while "data:" is rejected only when the literal substring onload appears in the URL value (/^data:.*onload/i). Because data: payloads are routinely Base64-encoded, the dangerous content (<script>, event handlers, etc.) is invisible to that substring test. A URL such as data:text/html;base64,… therefore survives in href / xlink:href, even though the decoded payload is active markup. This is an incomplete input-validation / sanitization defect in the sanitizer itself. This issue has been patched in version 1.0.15.
Severity
4.7 (Medium)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-28 20:39 UTC
CWE
- CWE-20 - Improper Input Validation
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://github.com/rhukster/dom-sanitizer/securit… | x_refsource_CONFIRM |
| https://github.com/rhukster/dom-sanitizer/commit/… | x_refsource_MISC |
| https://github.com/rhukster/dom-sanitizer/commit/… | x_refsource_MISC |
| https://github.com/rhukster/dom-sanitizer/release… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| rhukster | dom-sanitizer |
Affected:
< 1.0.15
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100370",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T20:39:56.823996Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T20:40:03.613Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/rhukster/dom-sanitizer/security/advisories/GHSA-wcj2-r6vg-rm97"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "dom-sanitizer",
"vendor": "rhukster",
"versions": [
{
"status": "affected",
"version": "\u003c 1.0.15"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.15, the isDangerousUrl() method is responsible for rejecting dangerous URL values in the href and xlink:href attributes. The weakness is that \"javascript:\" is rejected as a scheme, while \"data:\" is rejected only when the literal substring onload appears in the URL value (/^data:.*onload/i). Because data: payloads are routinely Base64-encoded, the dangerous content (\u003cscript\u003e, event handlers, etc.) is invisible to that substring test. A URL such as data:text/html;base64,\u2026 therefore survives in href / xlink:href, even though the decoded payload is active markup. This is an incomplete input-validation / sanitization defect in the sanitizer itself. This issue has been patched in version 1.0.15."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 4.7,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-20",
"description": "CWE-20: Improper Input Validation",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T20:07:09.470Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/rhukster/dom-sanitizer/security/advisories/GHSA-wcj2-r6vg-rm97",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/rhukster/dom-sanitizer/security/advisories/GHSA-wcj2-r6vg-rm97"
},
{
"name": "https://github.com/rhukster/dom-sanitizer/commit/10f97807e4501d60f63987f2e76a38cdbf312dcb",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/rhukster/dom-sanitizer/commit/10f97807e4501d60f63987f2e76a38cdbf312dcb"
},
{
"name": "https://github.com/rhukster/dom-sanitizer/commit/fb8f758b41134fc5fb2f563666f2330c69e31f94",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/rhukster/dom-sanitizer/commit/fb8f758b41134fc5fb2f563666f2330c69e31f94"
},
{
"name": "https://github.com/rhukster/dom-sanitizer/releases/tag/1.0.15",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/rhukster/dom-sanitizer/releases/tag/1.0.15"
}
],
"source": {
"advisory": "GHSA-wcj2-r6vg-rm97",
"discovery": "UNKNOWN"
},
"title": "DOMSanitizer - Incomplete data: URL Sanitization in DOMSanitizer::isDangerousUrl() Allows Base64-Encoded Payloads to Bypass href and xlink:href Validation"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-100370",
"datePublished": "2026-09-28T20:07:09.470Z",
"dateReserved": "2026-09-25T19:19:54.699Z",
"dateUpdated": "2026-09-28T20:40:03.613Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-40301 (GCVE-0-2026-40301)
Vulnerability from nvd – Published: 2026-04-17 20:51 – Updated: 2026-04-20 14:57
VLAI
EPSS
VEX
Title
rhukster/dom-sanitizer: SVG <style> tag allows CSS injection via unfiltered url() and @import directives
Summary
DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.10, DOMSanitizer::sanitize() allows <style> elements in SVG content but never inspects their text content. CSS url() references and @import rules pass through unfiltered, causing the browser to issue HTTP requests to attacker-controlled hosts when the sanitized SVG is rendered. Version 1.0.10 fixes the issue.
Severity
4.7 (Medium)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-04-20 14:42 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/rhukster/dom-sanitizer/securit… | x_refsource_CONFIRM |
| https://github.com/rhukster/dom-sanitizer/commit/… | x_refsource_MISC |
| https://github.com/rhukster/dom-sanitizer/release… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| rhukster | dom-sanitizer |
Affected:
< 1.0.10
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-40301",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-04-20T14:42:31.756128Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-04-20T14:57:39.192Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "dom-sanitizer",
"vendor": "rhukster",
"versions": [
{
"status": "affected",
"version": "\u003c 1.0.10"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.10, DOMSanitizer::sanitize() allows \u003cstyle\u003e elements in SVG content but never inspects their text content. CSS url() references and @import rules pass through unfiltered, causing the browser to issue HTTP requests to attacker-controlled hosts when the sanitized SVG is rendered. Version 1.0.10 fixes the issue."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 4.7,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-04-17T20:51:37.226Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/rhukster/dom-sanitizer/security/advisories/GHSA-93vf-569f-22cq",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/rhukster/dom-sanitizer/security/advisories/GHSA-93vf-569f-22cq"
},
{
"name": "https://github.com/rhukster/dom-sanitizer/commit/49a98046b708a4c92f754f5b0ef1720bb85142e2",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/rhukster/dom-sanitizer/commit/49a98046b708a4c92f754f5b0ef1720bb85142e2"
},
{
"name": "https://github.com/rhukster/dom-sanitizer/releases/tag/1.0.10",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/rhukster/dom-sanitizer/releases/tag/1.0.10"
}
],
"source": {
"advisory": "GHSA-93vf-569f-22cq",
"discovery": "UNKNOWN"
},
"title": "rhukster/dom-sanitizer: SVG \u003cstyle\u003e tag allows CSS injection via unfiltered url() and @import directives"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-40301",
"datePublished": "2026-04-17T20:51:37.226Z",
"dateReserved": "2026-04-10T20:22:44.036Z",
"dateUpdated": "2026-04-20T14:57:39.192Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103687 (GCVE-0-2026-103687)
Vulnerability from cvelistv5 – Published: 2026-10-01 14:30 – Updated: 2026-10-01 15:07 X_Open Source
VLAI
EPSS
VEX
Title
rhukster dom-sanitizer SVG Sanitization DOMSanitizer.php url incomplete blacklist
Summary
A vulnerability has been found in rhukster dom-sanitizer up to 1.0.15. The affected element is the function url of the file src/DOMSanitizer.php of the component SVG Sanitization. Such manipulation leads to incomplete blacklist. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.16 is sufficient to fix this issue. The name of the patch is 139c46c3d7c9bc81542b7b5a58d5cde5d0e0195a. Upgrading the affected component is recommended.
Severity
SSVC
Exploitation: poc
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 15:06 UTC
Assigner
References
8 references
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/412551 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/412551/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-103687 | third-party-advisory |
| https://vuldb.com/submit/958345 | third-party-advisory |
| https://github.com/rhukster/dom-sanitizer/securit… | exploit |
| https://github.com/rhukster/dom-sanitizer/commit/… | patch |
| https://github.com/rhukster/dom-sanitizer/release… | patch |
| https://github.com/rhukster/dom-sanitizer/ | product |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| rhukster | dom-sanitizer |
Affected:
1.0.0
Affected: 1.0.1 Affected: 1.0.2 Affected: 1.0.3 Affected: 1.0.4 Affected: 1.0.5 Affected: 1.0.6 Affected: 1.0.7 Affected: 1.0.8 Affected: 1.0.9 Affected: 1.0.10 Affected: 1.0.11 Affected: 1.0.12 Affected: 1.0.13 Affected: 1.0.14 Affected: 1.0.15 Unaffected: 1.0.16 cpe:2.3:a:rhukster:dom-sanitizer:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103687",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:06:52.309985Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T15:07:06.705Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:rhukster:dom-sanitizer:*:*:*:*:*:*:*:*"
],
"modules": [
"SVG Sanitization"
],
"product": "dom-sanitizer",
"vendor": "rhukster",
"versions": [
{
"status": "affected",
"version": "1.0.0"
},
{
"status": "affected",
"version": "1.0.1"
},
{
"status": "affected",
"version": "1.0.2"
},
{
"status": "affected",
"version": "1.0.3"
},
{
"status": "affected",
"version": "1.0.4"
},
{
"status": "affected",
"version": "1.0.5"
},
{
"status": "affected",
"version": "1.0.6"
},
{
"status": "affected",
"version": "1.0.7"
},
{
"status": "affected",
"version": "1.0.8"
},
{
"status": "affected",
"version": "1.0.9"
},
{
"status": "affected",
"version": "1.0.10"
},
{
"status": "affected",
"version": "1.0.11"
},
{
"status": "affected",
"version": "1.0.12"
},
{
"status": "affected",
"version": "1.0.13"
},
{
"status": "affected",
"version": "1.0.14"
},
{
"status": "affected",
"version": "1.0.15"
},
{
"status": "unaffected",
"version": "1.0.16"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "0xMo-Error (VulDB User)"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability has been found in rhukster dom-sanitizer up to 1.0.15. The affected element is the function url of the file src/DOMSanitizer.php of the component SVG Sanitization. Such manipulation leads to incomplete blacklist. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.16 is sufficient to fix this issue. The name of the patch is 139c46c3d7c9bc81542b7b5a58d5cde5d0e0195a. Upgrading the affected component is recommended."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-184",
"description": "Incomplete Blacklist",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-183",
"description": "Permissive List of Allowed Inputs",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T14:30:12.624Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-412551 | rhukster dom-sanitizer SVG Sanitization DOMSanitizer.php url incomplete blacklist",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/412551"
},
{
"name": "VDB-412551 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/412551/cti"
},
{
"name": "CVE-2026-103687 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-103687"
},
{
"name": "Submit #958345 | rhukster dom-sanitizer \u003c= 1.0.15 Improper Input Validation",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/958345"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/rhukster/dom-sanitizer/security/advisories/GHSA-cjfg-j8jp-5xvc"
},
{
"tags": [
"patch"
],
"url": "https://github.com/rhukster/dom-sanitizer/commit/139c46c3d7c9bc81542b7b5a58d5cde5d0e0195a"
},
{
"tags": [
"patch"
],
"url": "https://github.com/rhukster/dom-sanitizer/releases/tag/1.0.16"
},
{
"tags": [
"product"
],
"url": "https://github.com/rhukster/dom-sanitizer/"
}
],
"tags": [
"x_open-source"
],
"timeline": [
{
"lang": "en",
"time": "2026-10-01T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-10-01T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-10-01T11:36:45.000Z",
"value": "VulDB entry last update"
}
],
"title": "rhukster dom-sanitizer SVG Sanitization DOMSanitizer.php url incomplete blacklist",
"x_generator": [
"VulDB PVTS v202610"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-103687",
"datePublished": "2026-10-01T14:30:12.624Z",
"dateReserved": "2026-10-01T09:31:35.763Z",
"dateUpdated": "2026-10-01T15:07:06.705Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103686 (GCVE-0-2026-103686)
Vulnerability from cvelistv5 – Published: 2026-10-01 13:45 – Updated: 2026-10-01 13:45 X_Open Source
VLAI
EPSS
VEX
Title
rhukster dom-sanitizer URL Validation DOMSanitizer.php isDangerousUrl cross site scripting
Summary
A flaw has been found in rhukster dom-sanitizer up to 1.0.15. Impacted is the function DOMSanitizer::isDangerousUrl of the file src/DOMSanitizer.php of the component URL Validation. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be used. Upgrading to version 1.0.16 is recommended to address this issue. Patch name: 4623b565d060bc02ca5a07d8c8241fe28e2edfda. It is suggested to upgrade the affected component.
Severity
Assigner
References
8 references
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/412550 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/412550/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-103686 | third-party-advisory |
| https://vuldb.com/submit/958312 | third-party-advisory |
| https://github.com/rhukster/dom-sanitizer/securit… | exploit |
| https://github.com/rhukster/dom-sanitizer/commit/… | patch |
| https://github.com/rhukster/dom-sanitizer/release… | patch |
| https://github.com/rhukster/dom-sanitizer/ | product |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| rhukster | dom-sanitizer |
Affected:
1.0.0
Affected: 1.0.1 Affected: 1.0.2 Affected: 1.0.3 Affected: 1.0.4 Affected: 1.0.5 Affected: 1.0.6 Affected: 1.0.7 Affected: 1.0.8 Affected: 1.0.9 Affected: 1.0.10 Affected: 1.0.11 Affected: 1.0.12 Affected: 1.0.13 Affected: 1.0.14 Affected: 1.0.15 Unaffected: 1.0.16 cpe:2.3:a:rhukster:dom-sanitizer:*:*:*:*:*:*:*:* |
{
"containers": {
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:rhukster:dom-sanitizer:*:*:*:*:*:*:*:*"
],
"modules": [
"URL Validation"
],
"product": "dom-sanitizer",
"vendor": "rhukster",
"versions": [
{
"status": "affected",
"version": "1.0.0"
},
{
"status": "affected",
"version": "1.0.1"
},
{
"status": "affected",
"version": "1.0.2"
},
{
"status": "affected",
"version": "1.0.3"
},
{
"status": "affected",
"version": "1.0.4"
},
{
"status": "affected",
"version": "1.0.5"
},
{
"status": "affected",
"version": "1.0.6"
},
{
"status": "affected",
"version": "1.0.7"
},
{
"status": "affected",
"version": "1.0.8"
},
{
"status": "affected",
"version": "1.0.9"
},
{
"status": "affected",
"version": "1.0.10"
},
{
"status": "affected",
"version": "1.0.11"
},
{
"status": "affected",
"version": "1.0.12"
},
{
"status": "affected",
"version": "1.0.13"
},
{
"status": "affected",
"version": "1.0.14"
},
{
"status": "affected",
"version": "1.0.15"
},
{
"status": "unaffected",
"version": "1.0.16"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "0xMo-Error (VulDB User)"
}
],
"descriptions": [
{
"lang": "en",
"value": "A flaw has been found in rhukster dom-sanitizer up to 1.0.15. Impacted is the function DOMSanitizer::isDangerousUrl of the file src/DOMSanitizer.php of the component URL Validation. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be used. Upgrading to version 1.0.16 is recommended to address this issue. Patch name: 4623b565d060bc02ca5a07d8c8241fe28e2edfda. It is suggested to upgrade the affected component."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 3.5,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 3.5,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 4,
"vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:OF/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Cross Site Scripting",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-94",
"description": "Code Injection",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T13:45:12.259Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-412550 | rhukster dom-sanitizer URL Validation DOMSanitizer.php isDangerousUrl cross site scripting",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/412550"
},
{
"name": "VDB-412550 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/412550/cti"
},
{
"name": "CVE-2026-103686 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-103686"
},
{
"name": "Submit #958312 | rhukster dom-sanitizer \u003c= 1.0.15 Improper Input Validation",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/958312"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/rhukster/dom-sanitizer/security/advisories/GHSA-mrpv-6x26-mf6c"
},
{
"tags": [
"patch"
],
"url": "https://github.com/rhukster/dom-sanitizer/commit/4623b565d060bc02ca5a07d8c8241fe28e2edfda"
},
{
"tags": [
"patch"
],
"url": "https://github.com/rhukster/dom-sanitizer/releases/tag/1.0.16"
},
{
"tags": [
"product"
],
"url": "https://github.com/rhukster/dom-sanitizer/"
}
],
"tags": [
"x_open-source"
],
"timeline": [
{
"lang": "en",
"time": "2026-10-01T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-10-01T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-10-01T11:36:41.000Z",
"value": "VulDB entry last update"
}
],
"title": "rhukster dom-sanitizer URL Validation DOMSanitizer.php isDangerousUrl cross site scripting",
"x_generator": [
"VulDB PVTS v202610"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-103686",
"datePublished": "2026-10-01T13:45:12.259Z",
"dateReserved": "2026-10-01T09:31:30.531Z",
"dateUpdated": "2026-10-01T13:45:12.259Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100370 (GCVE-0-2026-100370)
Vulnerability from cvelistv5 – Published: 2026-09-28 20:07 – Updated: 2026-09-28 20:40
VLAI
EPSS
VEX
Title
DOMSanitizer - Incomplete data: URL Sanitization in DOMSanitizer::isDangerousUrl() Allows Base64-Encoded Payloads to Bypass href and xlink:href Validation
Summary
DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.15, the isDangerousUrl() method is responsible for rejecting dangerous URL values in the href and xlink:href attributes. The weakness is that "javascript:" is rejected as a scheme, while "data:" is rejected only when the literal substring onload appears in the URL value (/^data:.*onload/i). Because data: payloads are routinely Base64-encoded, the dangerous content (<script>, event handlers, etc.) is invisible to that substring test. A URL such as data:text/html;base64,… therefore survives in href / xlink:href, even though the decoded payload is active markup. This is an incomplete input-validation / sanitization defect in the sanitizer itself. This issue has been patched in version 1.0.15.
Severity
4.7 (Medium)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-28 20:39 UTC
CWE
- CWE-20 - Improper Input Validation
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://github.com/rhukster/dom-sanitizer/securit… | x_refsource_CONFIRM |
| https://github.com/rhukster/dom-sanitizer/commit/… | x_refsource_MISC |
| https://github.com/rhukster/dom-sanitizer/commit/… | x_refsource_MISC |
| https://github.com/rhukster/dom-sanitizer/release… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| rhukster | dom-sanitizer |
Affected:
< 1.0.15
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100370",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T20:39:56.823996Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T20:40:03.613Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/rhukster/dom-sanitizer/security/advisories/GHSA-wcj2-r6vg-rm97"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "dom-sanitizer",
"vendor": "rhukster",
"versions": [
{
"status": "affected",
"version": "\u003c 1.0.15"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.15, the isDangerousUrl() method is responsible for rejecting dangerous URL values in the href and xlink:href attributes. The weakness is that \"javascript:\" is rejected as a scheme, while \"data:\" is rejected only when the literal substring onload appears in the URL value (/^data:.*onload/i). Because data: payloads are routinely Base64-encoded, the dangerous content (\u003cscript\u003e, event handlers, etc.) is invisible to that substring test. A URL such as data:text/html;base64,\u2026 therefore survives in href / xlink:href, even though the decoded payload is active markup. This is an incomplete input-validation / sanitization defect in the sanitizer itself. This issue has been patched in version 1.0.15."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 4.7,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-20",
"description": "CWE-20: Improper Input Validation",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T20:07:09.470Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/rhukster/dom-sanitizer/security/advisories/GHSA-wcj2-r6vg-rm97",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/rhukster/dom-sanitizer/security/advisories/GHSA-wcj2-r6vg-rm97"
},
{
"name": "https://github.com/rhukster/dom-sanitizer/commit/10f97807e4501d60f63987f2e76a38cdbf312dcb",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/rhukster/dom-sanitizer/commit/10f97807e4501d60f63987f2e76a38cdbf312dcb"
},
{
"name": "https://github.com/rhukster/dom-sanitizer/commit/fb8f758b41134fc5fb2f563666f2330c69e31f94",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/rhukster/dom-sanitizer/commit/fb8f758b41134fc5fb2f563666f2330c69e31f94"
},
{
"name": "https://github.com/rhukster/dom-sanitizer/releases/tag/1.0.15",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/rhukster/dom-sanitizer/releases/tag/1.0.15"
}
],
"source": {
"advisory": "GHSA-wcj2-r6vg-rm97",
"discovery": "UNKNOWN"
},
"title": "DOMSanitizer - Incomplete data: URL Sanitization in DOMSanitizer::isDangerousUrl() Allows Base64-Encoded Payloads to Bypass href and xlink:href Validation"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-100370",
"datePublished": "2026-09-28T20:07:09.470Z",
"dateReserved": "2026-09-25T19:19:54.699Z",
"dateUpdated": "2026-09-28T20:40:03.613Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-40301 (GCVE-0-2026-40301)
Vulnerability from cvelistv5 – Published: 2026-04-17 20:51 – Updated: 2026-04-20 14:57
VLAI
EPSS
VEX
Title
rhukster/dom-sanitizer: SVG <style> tag allows CSS injection via unfiltered url() and @import directives
Summary
DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.10, DOMSanitizer::sanitize() allows <style> elements in SVG content but never inspects their text content. CSS url() references and @import rules pass through unfiltered, causing the browser to issue HTTP requests to attacker-controlled hosts when the sanitized SVG is rendered. Version 1.0.10 fixes the issue.
Severity
4.7 (Medium)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-04-20 14:42 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/rhukster/dom-sanitizer/securit… | x_refsource_CONFIRM |
| https://github.com/rhukster/dom-sanitizer/commit/… | x_refsource_MISC |
| https://github.com/rhukster/dom-sanitizer/release… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| rhukster | dom-sanitizer |
Affected:
< 1.0.10
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-40301",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-04-20T14:42:31.756128Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-04-20T14:57:39.192Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "dom-sanitizer",
"vendor": "rhukster",
"versions": [
{
"status": "affected",
"version": "\u003c 1.0.10"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.10, DOMSanitizer::sanitize() allows \u003cstyle\u003e elements in SVG content but never inspects their text content. CSS url() references and @import rules pass through unfiltered, causing the browser to issue HTTP requests to attacker-controlled hosts when the sanitized SVG is rendered. Version 1.0.10 fixes the issue."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 4.7,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-04-17T20:51:37.226Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/rhukster/dom-sanitizer/security/advisories/GHSA-93vf-569f-22cq",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/rhukster/dom-sanitizer/security/advisories/GHSA-93vf-569f-22cq"
},
{
"name": "https://github.com/rhukster/dom-sanitizer/commit/49a98046b708a4c92f754f5b0ef1720bb85142e2",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/rhukster/dom-sanitizer/commit/49a98046b708a4c92f754f5b0ef1720bb85142e2"
},
{
"name": "https://github.com/rhukster/dom-sanitizer/releases/tag/1.0.10",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/rhukster/dom-sanitizer/releases/tag/1.0.10"
}
],
"source": {
"advisory": "GHSA-93vf-569f-22cq",
"discovery": "UNKNOWN"
},
"title": "rhukster/dom-sanitizer: SVG \u003cstyle\u003e tag allows CSS injection via unfiltered url() and @import directives"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-40301",
"datePublished": "2026-04-17T20:51:37.226Z",
"dateReserved": "2026-04-10T20:22:44.036Z",
"dateUpdated": "2026-04-20T14:57:39.192Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}