DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3.
CVSS Details
- CVSS 3.1 Base Score: 10
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade grafana-selinuxUpgrade grafana | Oct 24, 2024 | Oct 11, 2024 |
| Atlassian Jira | — | Upgrade to the latest version of Atlassian JIRA | Apr 22, 2026 | Apr 21, 2026 |
| Debian | — | Upgrade node-dompurifyUpgrade cacti | Oct 15, 2024 | Oct 11, 2024 |
| Oracle_linux | — | Upgrade grafanaUpgrade grafana-selinux | Nov 11, 2024 | Oct 11, 2024 |
| Redhat_linux | — | Upgrade grafana-debuginfoUpgrade grafanaUpgrade grafana-debugsourceUpgrade grafana-selinux | Oct 23, 2024 | Oct 11, 2024 |
| Rocky_linux | — | Upgrade grafana-selinuxUpgrade grafana-debuginfoUpgrade grafanaUpgrade grafana-debugsource | Nov 4, 2024 | Oct 11, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub