Search

Find a vulnerability

Search criteria

    8 vulnerabilities by rhukster

    CVE-2026-103687 (GCVE-0-2026-103687)

    Vulnerability from nvd – Published: 2026-10-01 14:30 – Updated: 2026-10-01 15:07 X_Open Source
    VLAI
    Title
    rhukster dom-sanitizer SVG Sanitization DOMSanitizer.php url incomplete blacklist
    Summary
    A vulnerability has been found in rhukster dom-sanitizer up to 1.0.15. The affected element is the function url of the file src/DOMSanitizer.php of the component SVG Sanitization. Such manipulation leads to incomplete blacklist. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.16 is sufficient to fix this issue. The name of the patch is 139c46c3d7c9bc81542b7b5a58d5cde5d0e0195a. Upgrading the affected component is recommended.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-01 15:06 UTC
    CWE
    • CWE-184 - Incomplete Blacklist
    • CWE-183 - Permissive List of Allowed Inputs
    Impacted products
    Vendor Product Version
    rhukster dom-sanitizer Affected: 1.0.0
    Affected: 1.0.1
    Affected: 1.0.2
    Affected: 1.0.3
    Affected: 1.0.4
    Affected: 1.0.5
    Affected: 1.0.6
    Affected: 1.0.7
    Affected: 1.0.8
    Affected: 1.0.9
    Affected: 1.0.10
    Affected: 1.0.11
    Affected: 1.0.12
    Affected: 1.0.13
    Affected: 1.0.14
    Affected: 1.0.15
    Unaffected: 1.0.16
        cpe:2.3:a:rhukster:dom-sanitizer:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-103687",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-01T15:06:52.309985Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-01T15:07:06.705Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:rhukster:dom-sanitizer:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "SVG Sanitization"
              ],
              "product": "dom-sanitizer",
              "vendor": "rhukster",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0.0"
                },
                {
                  "status": "affected",
                  "version": "1.0.1"
                },
                {
                  "status": "affected",
                  "version": "1.0.2"
                },
                {
                  "status": "affected",
                  "version": "1.0.3"
                },
                {
                  "status": "affected",
                  "version": "1.0.4"
                },
                {
                  "status": "affected",
                  "version": "1.0.5"
                },
                {
                  "status": "affected",
                  "version": "1.0.6"
                },
                {
                  "status": "affected",
                  "version": "1.0.7"
                },
                {
                  "status": "affected",
                  "version": "1.0.8"
                },
                {
                  "status": "affected",
                  "version": "1.0.9"
                },
                {
                  "status": "affected",
                  "version": "1.0.10"
                },
                {
                  "status": "affected",
                  "version": "1.0.11"
                },
                {
                  "status": "affected",
                  "version": "1.0.12"
                },
                {
                  "status": "affected",
                  "version": "1.0.13"
                },
                {
                  "status": "affected",
                  "version": "1.0.14"
                },
                {
                  "status": "affected",
                  "version": "1.0.15"
                },
                {
                  "status": "unaffected",
                  "version": "1.0.16"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "0xMo-Error (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability has been found in rhukster dom-sanitizer up to 1.0.15. The affected element is the function url of the file src/DOMSanitizer.php of the component SVG Sanitization. Such manipulation leads to incomplete blacklist. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.16 is sufficient to fix this issue. The name of the patch is 139c46c3d7c9bc81542b7b5a58d5cde5d0e0195a. Upgrading the affected component is recommended."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 7.5,
                "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-184",
                  "description": "Incomplete Blacklist",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-183",
                  "description": "Permissive List of Allowed Inputs",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T14:30:12.624Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-412551 | rhukster dom-sanitizer SVG Sanitization DOMSanitizer.php url incomplete blacklist",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/412551"
            },
            {
              "name": "VDB-412551 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/412551/cti"
            },
            {
              "name": "CVE-2026-103687 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-103687"
            },
            {
              "name": "Submit #958345 | rhukster dom-sanitizer \u003c= 1.0.15 Improper Input Validation",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/958345"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://github.com/rhukster/dom-sanitizer/security/advisories/GHSA-cjfg-j8jp-5xvc"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/rhukster/dom-sanitizer/commit/139c46c3d7c9bc81542b7b5a58d5cde5d0e0195a"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/rhukster/dom-sanitizer/releases/tag/1.0.16"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/rhukster/dom-sanitizer/"
            }
          ],
          "tags": [
            "x_open-source"
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-10-01T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-10-01T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-10-01T11:36:45.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "rhukster dom-sanitizer SVG Sanitization DOMSanitizer.php url incomplete blacklist",
          "x_generator": [
            "VulDB PVTS v202610"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-103687",
        "datePublished": "2026-10-01T14:30:12.624Z",
        "dateReserved": "2026-10-01T09:31:35.763Z",
        "dateUpdated": "2026-10-01T15:07:06.705Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-103686 (GCVE-0-2026-103686)

    Vulnerability from nvd – Published: 2026-10-01 13:45 – Updated: 2026-10-01 13:45 X_Open Source
    VLAI
    Title
    rhukster dom-sanitizer URL Validation DOMSanitizer.php isDangerousUrl cross site scripting
    Summary
    A flaw has been found in rhukster dom-sanitizer up to 1.0.15. Impacted is the function DOMSanitizer::isDangerousUrl of the file src/DOMSanitizer.php of the component URL Validation. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be used. Upgrading to version 1.0.16 is recommended to address this issue. Patch name: 4623b565d060bc02ca5a07d8c8241fe28e2edfda. It is suggested to upgrade the affected component.
    CWE
    Impacted products
    Vendor Product Version
    rhukster dom-sanitizer Affected: 1.0.0
    Affected: 1.0.1
    Affected: 1.0.2
    Affected: 1.0.3
    Affected: 1.0.4
    Affected: 1.0.5
    Affected: 1.0.6
    Affected: 1.0.7
    Affected: 1.0.8
    Affected: 1.0.9
    Affected: 1.0.10
    Affected: 1.0.11
    Affected: 1.0.12
    Affected: 1.0.13
    Affected: 1.0.14
    Affected: 1.0.15
    Unaffected: 1.0.16
        cpe:2.3:a:rhukster:dom-sanitizer:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:rhukster:dom-sanitizer:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "URL Validation"
              ],
              "product": "dom-sanitizer",
              "vendor": "rhukster",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0.0"
                },
                {
                  "status": "affected",
                  "version": "1.0.1"
                },
                {
                  "status": "affected",
                  "version": "1.0.2"
                },
                {
                  "status": "affected",
                  "version": "1.0.3"
                },
                {
                  "status": "affected",
                  "version": "1.0.4"
                },
                {
                  "status": "affected",
                  "version": "1.0.5"
                },
                {
                  "status": "affected",
                  "version": "1.0.6"
                },
                {
                  "status": "affected",
                  "version": "1.0.7"
                },
                {
                  "status": "affected",
                  "version": "1.0.8"
                },
                {
                  "status": "affected",
                  "version": "1.0.9"
                },
                {
                  "status": "affected",
                  "version": "1.0.10"
                },
                {
                  "status": "affected",
                  "version": "1.0.11"
                },
                {
                  "status": "affected",
                  "version": "1.0.12"
                },
                {
                  "status": "affected",
                  "version": "1.0.13"
                },
                {
                  "status": "affected",
                  "version": "1.0.14"
                },
                {
                  "status": "affected",
                  "version": "1.0.15"
                },
                {
                  "status": "unaffected",
                  "version": "1.0.16"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "0xMo-Error (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A flaw has been found in rhukster dom-sanitizer up to 1.0.15. Impacted is the function DOMSanitizer::isDangerousUrl of the file src/DOMSanitizer.php of the component URL Validation. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be used. Upgrading to version 1.0.16 is recommended to address this issue. Patch name: 4623b565d060bc02ca5a07d8c8241fe28e2edfda. It is suggested to upgrade the affected component."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.1,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 3.5,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 3.5,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 4,
                "vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:OF/RC:C",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "Cross Site Scripting",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-94",
                  "description": "Code Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T13:45:12.259Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-412550 | rhukster dom-sanitizer URL Validation DOMSanitizer.php isDangerousUrl cross site scripting",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/412550"
            },
            {
              "name": "VDB-412550 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/412550/cti"
            },
            {
              "name": "CVE-2026-103686 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-103686"
            },
            {
              "name": "Submit #958312 | rhukster dom-sanitizer \u003c= 1.0.15 Improper Input Validation",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/958312"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://github.com/rhukster/dom-sanitizer/security/advisories/GHSA-mrpv-6x26-mf6c"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/rhukster/dom-sanitizer/commit/4623b565d060bc02ca5a07d8c8241fe28e2edfda"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/rhukster/dom-sanitizer/releases/tag/1.0.16"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/rhukster/dom-sanitizer/"
            }
          ],
          "tags": [
            "x_open-source"
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-10-01T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-10-01T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-10-01T11:36:41.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "rhukster dom-sanitizer URL Validation DOMSanitizer.php isDangerousUrl cross site scripting",
          "x_generator": [
            "VulDB PVTS v202610"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-103686",
        "datePublished": "2026-10-01T13:45:12.259Z",
        "dateReserved": "2026-10-01T09:31:30.531Z",
        "dateUpdated": "2026-10-01T13:45:12.259Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-100370 (GCVE-0-2026-100370)

    Vulnerability from nvd – Published: 2026-09-28 20:07 – Updated: 2026-09-28 20:40
    VLAI
    Title
    DOMSanitizer - Incomplete data: URL Sanitization in DOMSanitizer::isDangerousUrl() Allows Base64-Encoded Payloads to Bypass href and xlink:href Validation
    Summary
    DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.15, the isDangerousUrl() method is responsible for rejecting dangerous URL values in the href and xlink:href attributes. The weakness is that "javascript:" is rejected as a scheme, while "data:" is rejected only when the literal substring onload appears in the URL value (/^data:.*onload/i). Because data: payloads are routinely Base64-encoded, the dangerous content (<script>, event handlers, etc.) is invisible to that substring test. A URL such as data:text/html;base64,… therefore survives in href / xlink:href, even though the decoded payload is active markup. This is an incomplete input-validation / sanitization defect in the sanitizer itself. This issue has been patched in version 1.0.15.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 20:39 UTC
    CWE
    • CWE-20 - Improper Input Validation
    Impacted products
    Vendor Product Version
    rhukster dom-sanitizer Affected: < 1.0.15
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-100370",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T20:39:56.823996Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T20:40:03.613Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/rhukster/dom-sanitizer/security/advisories/GHSA-wcj2-r6vg-rm97"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "dom-sanitizer",
              "vendor": "rhukster",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.0.15"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.15, the isDangerousUrl() method is responsible for rejecting dangerous URL values in the href and xlink:href attributes. The weakness is that \"javascript:\" is rejected as a scheme, while \"data:\" is rejected only when the literal substring onload appears in the URL value (/^data:.*onload/i). Because data: payloads are routinely Base64-encoded, the dangerous content (\u003cscript\u003e, event handlers, etc.) is invisible to that substring test. A URL such as data:text/html;base64,\u2026 therefore survives in href / xlink:href, even though the decoded payload is active markup. This is an incomplete input-validation / sanitization defect in the sanitizer itself. This issue has been patched in version 1.0.15."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 4.7,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20: Improper Input Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T20:07:09.470Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/rhukster/dom-sanitizer/security/advisories/GHSA-wcj2-r6vg-rm97",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/rhukster/dom-sanitizer/security/advisories/GHSA-wcj2-r6vg-rm97"
            },
            {
              "name": "https://github.com/rhukster/dom-sanitizer/commit/10f97807e4501d60f63987f2e76a38cdbf312dcb",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/rhukster/dom-sanitizer/commit/10f97807e4501d60f63987f2e76a38cdbf312dcb"
            },
            {
              "name": "https://github.com/rhukster/dom-sanitizer/commit/fb8f758b41134fc5fb2f563666f2330c69e31f94",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/rhukster/dom-sanitizer/commit/fb8f758b41134fc5fb2f563666f2330c69e31f94"
            },
            {
              "name": "https://github.com/rhukster/dom-sanitizer/releases/tag/1.0.15",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/rhukster/dom-sanitizer/releases/tag/1.0.15"
            }
          ],
          "source": {
            "advisory": "GHSA-wcj2-r6vg-rm97",
            "discovery": "UNKNOWN"
          },
          "title": "DOMSanitizer - Incomplete data: URL Sanitization in DOMSanitizer::isDangerousUrl() Allows Base64-Encoded Payloads to Bypass href and xlink:href Validation"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-100370",
        "datePublished": "2026-09-28T20:07:09.470Z",
        "dateReserved": "2026-09-25T19:19:54.699Z",
        "dateUpdated": "2026-09-28T20:40:03.613Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-40301 (GCVE-0-2026-40301)

    Vulnerability from nvd – Published: 2026-04-17 20:51 – Updated: 2026-04-20 14:57
    VLAI
    Title
    rhukster/dom-sanitizer: SVG <style> tag allows CSS injection via unfiltered url() and @import directives
    Summary
    DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.10, DOMSanitizer::sanitize() allows <style> elements in SVG content but never inspects their text content. CSS url() references and @import rules pass through unfiltered, causing the browser to issue HTTP requests to attacker-controlled hosts when the sanitized SVG is rendered. Version 1.0.10 fixes the issue.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-04-20 14:42 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Vendor Product Version
    rhukster dom-sanitizer Affected: < 1.0.10
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-40301",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-04-20T14:42:31.756128Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-04-20T14:57:39.192Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "dom-sanitizer",
              "vendor": "rhukster",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.0.10"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.10, DOMSanitizer::sanitize() allows \u003cstyle\u003e elements in SVG content but never inspects their text content. CSS url() references and @import rules pass through unfiltered, causing the browser to issue HTTP requests to attacker-controlled hosts when the sanitized SVG is rendered. Version 1.0.10 fixes the issue."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 4.7,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-04-17T20:51:37.226Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/rhukster/dom-sanitizer/security/advisories/GHSA-93vf-569f-22cq",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/rhukster/dom-sanitizer/security/advisories/GHSA-93vf-569f-22cq"
            },
            {
              "name": "https://github.com/rhukster/dom-sanitizer/commit/49a98046b708a4c92f754f5b0ef1720bb85142e2",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/rhukster/dom-sanitizer/commit/49a98046b708a4c92f754f5b0ef1720bb85142e2"
            },
            {
              "name": "https://github.com/rhukster/dom-sanitizer/releases/tag/1.0.10",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/rhukster/dom-sanitizer/releases/tag/1.0.10"
            }
          ],
          "source": {
            "advisory": "GHSA-93vf-569f-22cq",
            "discovery": "UNKNOWN"
          },
          "title": "rhukster/dom-sanitizer: SVG \u003cstyle\u003e tag allows CSS injection via unfiltered url() and @import directives"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-40301",
        "datePublished": "2026-04-17T20:51:37.226Z",
        "dateReserved": "2026-04-10T20:22:44.036Z",
        "dateUpdated": "2026-04-20T14:57:39.192Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-103687 (GCVE-0-2026-103687)

    Vulnerability from cvelistv5 – Published: 2026-10-01 14:30 – Updated: 2026-10-01 15:07 X_Open Source
    VLAI
    Title
    rhukster dom-sanitizer SVG Sanitization DOMSanitizer.php url incomplete blacklist
    Summary
    A vulnerability has been found in rhukster dom-sanitizer up to 1.0.15. The affected element is the function url of the file src/DOMSanitizer.php of the component SVG Sanitization. Such manipulation leads to incomplete blacklist. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.16 is sufficient to fix this issue. The name of the patch is 139c46c3d7c9bc81542b7b5a58d5cde5d0e0195a. Upgrading the affected component is recommended.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-01 15:06 UTC
    CWE
    • CWE-184 - Incomplete Blacklist
    • CWE-183 - Permissive List of Allowed Inputs
    Impacted products
    Vendor Product Version
    rhukster dom-sanitizer Affected: 1.0.0
    Affected: 1.0.1
    Affected: 1.0.2
    Affected: 1.0.3
    Affected: 1.0.4
    Affected: 1.0.5
    Affected: 1.0.6
    Affected: 1.0.7
    Affected: 1.0.8
    Affected: 1.0.9
    Affected: 1.0.10
    Affected: 1.0.11
    Affected: 1.0.12
    Affected: 1.0.13
    Affected: 1.0.14
    Affected: 1.0.15
    Unaffected: 1.0.16
        cpe:2.3:a:rhukster:dom-sanitizer:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-103687",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-01T15:06:52.309985Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-01T15:07:06.705Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:rhukster:dom-sanitizer:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "SVG Sanitization"
              ],
              "product": "dom-sanitizer",
              "vendor": "rhukster",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0.0"
                },
                {
                  "status": "affected",
                  "version": "1.0.1"
                },
                {
                  "status": "affected",
                  "version": "1.0.2"
                },
                {
                  "status": "affected",
                  "version": "1.0.3"
                },
                {
                  "status": "affected",
                  "version": "1.0.4"
                },
                {
                  "status": "affected",
                  "version": "1.0.5"
                },
                {
                  "status": "affected",
                  "version": "1.0.6"
                },
                {
                  "status": "affected",
                  "version": "1.0.7"
                },
                {
                  "status": "affected",
                  "version": "1.0.8"
                },
                {
                  "status": "affected",
                  "version": "1.0.9"
                },
                {
                  "status": "affected",
                  "version": "1.0.10"
                },
                {
                  "status": "affected",
                  "version": "1.0.11"
                },
                {
                  "status": "affected",
                  "version": "1.0.12"
                },
                {
                  "status": "affected",
                  "version": "1.0.13"
                },
                {
                  "status": "affected",
                  "version": "1.0.14"
                },
                {
                  "status": "affected",
                  "version": "1.0.15"
                },
                {
                  "status": "unaffected",
                  "version": "1.0.16"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "0xMo-Error (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability has been found in rhukster dom-sanitizer up to 1.0.15. The affected element is the function url of the file src/DOMSanitizer.php of the component SVG Sanitization. Such manipulation leads to incomplete blacklist. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.16 is sufficient to fix this issue. The name of the patch is 139c46c3d7c9bc81542b7b5a58d5cde5d0e0195a. Upgrading the affected component is recommended."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 7.5,
                "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-184",
                  "description": "Incomplete Blacklist",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-183",
                  "description": "Permissive List of Allowed Inputs",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T14:30:12.624Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-412551 | rhukster dom-sanitizer SVG Sanitization DOMSanitizer.php url incomplete blacklist",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/412551"
            },
            {
              "name": "VDB-412551 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/412551/cti"
            },
            {
              "name": "CVE-2026-103687 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-103687"
            },
            {
              "name": "Submit #958345 | rhukster dom-sanitizer \u003c= 1.0.15 Improper Input Validation",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/958345"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://github.com/rhukster/dom-sanitizer/security/advisories/GHSA-cjfg-j8jp-5xvc"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/rhukster/dom-sanitizer/commit/139c46c3d7c9bc81542b7b5a58d5cde5d0e0195a"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/rhukster/dom-sanitizer/releases/tag/1.0.16"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/rhukster/dom-sanitizer/"
            }
          ],
          "tags": [
            "x_open-source"
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-10-01T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-10-01T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-10-01T11:36:45.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "rhukster dom-sanitizer SVG Sanitization DOMSanitizer.php url incomplete blacklist",
          "x_generator": [
            "VulDB PVTS v202610"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-103687",
        "datePublished": "2026-10-01T14:30:12.624Z",
        "dateReserved": "2026-10-01T09:31:35.763Z",
        "dateUpdated": "2026-10-01T15:07:06.705Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-103686 (GCVE-0-2026-103686)

    Vulnerability from cvelistv5 – Published: 2026-10-01 13:45 – Updated: 2026-10-01 13:45 X_Open Source
    VLAI
    Title
    rhukster dom-sanitizer URL Validation DOMSanitizer.php isDangerousUrl cross site scripting
    Summary
    A flaw has been found in rhukster dom-sanitizer up to 1.0.15. Impacted is the function DOMSanitizer::isDangerousUrl of the file src/DOMSanitizer.php of the component URL Validation. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be used. Upgrading to version 1.0.16 is recommended to address this issue. Patch name: 4623b565d060bc02ca5a07d8c8241fe28e2edfda. It is suggested to upgrade the affected component.
    CWE
    Impacted products
    Vendor Product Version
    rhukster dom-sanitizer Affected: 1.0.0
    Affected: 1.0.1
    Affected: 1.0.2
    Affected: 1.0.3
    Affected: 1.0.4
    Affected: 1.0.5
    Affected: 1.0.6
    Affected: 1.0.7
    Affected: 1.0.8
    Affected: 1.0.9
    Affected: 1.0.10
    Affected: 1.0.11
    Affected: 1.0.12
    Affected: 1.0.13
    Affected: 1.0.14
    Affected: 1.0.15
    Unaffected: 1.0.16
        cpe:2.3:a:rhukster:dom-sanitizer:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:rhukster:dom-sanitizer:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "URL Validation"
              ],
              "product": "dom-sanitizer",
              "vendor": "rhukster",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0.0"
                },
                {
                  "status": "affected",
                  "version": "1.0.1"
                },
                {
                  "status": "affected",
                  "version": "1.0.2"
                },
                {
                  "status": "affected",
                  "version": "1.0.3"
                },
                {
                  "status": "affected",
                  "version": "1.0.4"
                },
                {
                  "status": "affected",
                  "version": "1.0.5"
                },
                {
                  "status": "affected",
                  "version": "1.0.6"
                },
                {
                  "status": "affected",
                  "version": "1.0.7"
                },
                {
                  "status": "affected",
                  "version": "1.0.8"
                },
                {
                  "status": "affected",
                  "version": "1.0.9"
                },
                {
                  "status": "affected",
                  "version": "1.0.10"
                },
                {
                  "status": "affected",
                  "version": "1.0.11"
                },
                {
                  "status": "affected",
                  "version": "1.0.12"
                },
                {
                  "status": "affected",
                  "version": "1.0.13"
                },
                {
                  "status": "affected",
                  "version": "1.0.14"
                },
                {
                  "status": "affected",
                  "version": "1.0.15"
                },
                {
                  "status": "unaffected",
                  "version": "1.0.16"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "0xMo-Error (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A flaw has been found in rhukster dom-sanitizer up to 1.0.15. Impacted is the function DOMSanitizer::isDangerousUrl of the file src/DOMSanitizer.php of the component URL Validation. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be used. Upgrading to version 1.0.16 is recommended to address this issue. Patch name: 4623b565d060bc02ca5a07d8c8241fe28e2edfda. It is suggested to upgrade the affected component."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.1,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 3.5,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 3.5,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 4,
                "vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:OF/RC:C",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "Cross Site Scripting",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-94",
                  "description": "Code Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T13:45:12.259Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-412550 | rhukster dom-sanitizer URL Validation DOMSanitizer.php isDangerousUrl cross site scripting",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/412550"
            },
            {
              "name": "VDB-412550 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/412550/cti"
            },
            {
              "name": "CVE-2026-103686 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-103686"
            },
            {
              "name": "Submit #958312 | rhukster dom-sanitizer \u003c= 1.0.15 Improper Input Validation",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/958312"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://github.com/rhukster/dom-sanitizer/security/advisories/GHSA-mrpv-6x26-mf6c"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/rhukster/dom-sanitizer/commit/4623b565d060bc02ca5a07d8c8241fe28e2edfda"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/rhukster/dom-sanitizer/releases/tag/1.0.16"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/rhukster/dom-sanitizer/"
            }
          ],
          "tags": [
            "x_open-source"
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-10-01T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-10-01T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-10-01T11:36:41.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "rhukster dom-sanitizer URL Validation DOMSanitizer.php isDangerousUrl cross site scripting",
          "x_generator": [
            "VulDB PVTS v202610"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-103686",
        "datePublished": "2026-10-01T13:45:12.259Z",
        "dateReserved": "2026-10-01T09:31:30.531Z",
        "dateUpdated": "2026-10-01T13:45:12.259Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-100370 (GCVE-0-2026-100370)

    Vulnerability from cvelistv5 – Published: 2026-09-28 20:07 – Updated: 2026-09-28 20:40
    VLAI
    Title
    DOMSanitizer - Incomplete data: URL Sanitization in DOMSanitizer::isDangerousUrl() Allows Base64-Encoded Payloads to Bypass href and xlink:href Validation
    Summary
    DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.15, the isDangerousUrl() method is responsible for rejecting dangerous URL values in the href and xlink:href attributes. The weakness is that "javascript:" is rejected as a scheme, while "data:" is rejected only when the literal substring onload appears in the URL value (/^data:.*onload/i). Because data: payloads are routinely Base64-encoded, the dangerous content (<script>, event handlers, etc.) is invisible to that substring test. A URL such as data:text/html;base64,… therefore survives in href / xlink:href, even though the decoded payload is active markup. This is an incomplete input-validation / sanitization defect in the sanitizer itself. This issue has been patched in version 1.0.15.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 20:39 UTC
    CWE
    • CWE-20 - Improper Input Validation
    Impacted products
    Vendor Product Version
    rhukster dom-sanitizer Affected: < 1.0.15
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-100370",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T20:39:56.823996Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T20:40:03.613Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/rhukster/dom-sanitizer/security/advisories/GHSA-wcj2-r6vg-rm97"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "dom-sanitizer",
              "vendor": "rhukster",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.0.15"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.15, the isDangerousUrl() method is responsible for rejecting dangerous URL values in the href and xlink:href attributes. The weakness is that \"javascript:\" is rejected as a scheme, while \"data:\" is rejected only when the literal substring onload appears in the URL value (/^data:.*onload/i). Because data: payloads are routinely Base64-encoded, the dangerous content (\u003cscript\u003e, event handlers, etc.) is invisible to that substring test. A URL such as data:text/html;base64,\u2026 therefore survives in href / xlink:href, even though the decoded payload is active markup. This is an incomplete input-validation / sanitization defect in the sanitizer itself. This issue has been patched in version 1.0.15."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 4.7,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20: Improper Input Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T20:07:09.470Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/rhukster/dom-sanitizer/security/advisories/GHSA-wcj2-r6vg-rm97",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/rhukster/dom-sanitizer/security/advisories/GHSA-wcj2-r6vg-rm97"
            },
            {
              "name": "https://github.com/rhukster/dom-sanitizer/commit/10f97807e4501d60f63987f2e76a38cdbf312dcb",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/rhukster/dom-sanitizer/commit/10f97807e4501d60f63987f2e76a38cdbf312dcb"
            },
            {
              "name": "https://github.com/rhukster/dom-sanitizer/commit/fb8f758b41134fc5fb2f563666f2330c69e31f94",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/rhukster/dom-sanitizer/commit/fb8f758b41134fc5fb2f563666f2330c69e31f94"
            },
            {
              "name": "https://github.com/rhukster/dom-sanitizer/releases/tag/1.0.15",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/rhukster/dom-sanitizer/releases/tag/1.0.15"
            }
          ],
          "source": {
            "advisory": "GHSA-wcj2-r6vg-rm97",
            "discovery": "UNKNOWN"
          },
          "title": "DOMSanitizer - Incomplete data: URL Sanitization in DOMSanitizer::isDangerousUrl() Allows Base64-Encoded Payloads to Bypass href and xlink:href Validation"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-100370",
        "datePublished": "2026-09-28T20:07:09.470Z",
        "dateReserved": "2026-09-25T19:19:54.699Z",
        "dateUpdated": "2026-09-28T20:40:03.613Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-40301 (GCVE-0-2026-40301)

    Vulnerability from cvelistv5 – Published: 2026-04-17 20:51 – Updated: 2026-04-20 14:57
    VLAI
    Title
    rhukster/dom-sanitizer: SVG <style> tag allows CSS injection via unfiltered url() and @import directives
    Summary
    DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.10, DOMSanitizer::sanitize() allows <style> elements in SVG content but never inspects their text content. CSS url() references and @import rules pass through unfiltered, causing the browser to issue HTTP requests to attacker-controlled hosts when the sanitized SVG is rendered. Version 1.0.10 fixes the issue.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-04-20 14:42 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Vendor Product Version
    rhukster dom-sanitizer Affected: < 1.0.10
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-40301",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-04-20T14:42:31.756128Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-04-20T14:57:39.192Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "dom-sanitizer",
              "vendor": "rhukster",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.0.10"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.10, DOMSanitizer::sanitize() allows \u003cstyle\u003e elements in SVG content but never inspects their text content. CSS url() references and @import rules pass through unfiltered, causing the browser to issue HTTP requests to attacker-controlled hosts when the sanitized SVG is rendered. Version 1.0.10 fixes the issue."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 4.7,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-04-17T20:51:37.226Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/rhukster/dom-sanitizer/security/advisories/GHSA-93vf-569f-22cq",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/rhukster/dom-sanitizer/security/advisories/GHSA-93vf-569f-22cq"
            },
            {
              "name": "https://github.com/rhukster/dom-sanitizer/commit/49a98046b708a4c92f754f5b0ef1720bb85142e2",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/rhukster/dom-sanitizer/commit/49a98046b708a4c92f754f5b0ef1720bb85142e2"
            },
            {
              "name": "https://github.com/rhukster/dom-sanitizer/releases/tag/1.0.10",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/rhukster/dom-sanitizer/releases/tag/1.0.10"
            }
          ],
          "source": {
            "advisory": "GHSA-93vf-569f-22cq",
            "discovery": "UNKNOWN"
          },
          "title": "rhukster/dom-sanitizer: SVG \u003cstyle\u003e tag allows CSS injection via unfiltered url() and @import directives"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-40301",
        "datePublished": "2026-04-17T20:51:37.226Z",
        "dateReserved": "2026-04-10T20:22:44.036Z",
        "dateUpdated": "2026-04-20T14:57:39.192Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }