CVE-2026-66010: DOMPurify before 3.4.12 Hook Bypass via CUSTOM_ELEMENT_HANDLING
DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOMELEMENTHANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attributes on custom elements that later re-inject them into innerHTML sinks, creating second-order XSS gadgets.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66010?
The severity of CVE-2026-66010 is classified as medium with a score of 6.1.
How do I fix CVE-2026-66010?
To fix CVE-2026-66010, upgrade DOMPurify to version 3.4.12 or later.
What type of vulnerability is CVE-2026-66010?
CVE-2026-66010 is a Cross-Site Scripting (XSS) vulnerability.
What impact does CVE-2026-66010 have?
CVE-2026-66010 allows attackers to bypass application security policies and preserve sensitive attributes in custom elements.
What software is affected by CVE-2026-66010?
The affected software for CVE-2026-66010 is DOMPurify, specifically versions before 3.4.12.