CVE-2026-49458
MediumAdvisory
Published 15 Jun 2026In the index since 6 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.1
- base score, highest
- EPSS
- 0.004
- 34th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 63
- of 17,781 indexed, latest versions
- Container images
- 56
- deployed by those charts
- Fix available
- 1 of 1
- affected package
DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks
Carried by container images the latest versions of 63 of 17,781 indexed charts deploy, on 56 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| dompurifynpm | 2.1.1, 2.2.6, 2.2.7, 2.3.1+25 more | 3.4.6 | 56 |
- OSV records
- GHSA-hpcv-96wg-7vj8
Charts affected
63 by stars
Container images carrying it
56 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | 58d377933678 | dompurify | 3.4.6 | 1 |
| ghcr.io/ | dcfd14877740 | dompurify | 3.4.6 | 1 |
| ghcr.io/ | 51ee22428b41 | dompurify | 3.4.6 | 1 |
| quay.io/ | abdb6b08815d | dompurify | 3.4.6 | 1 |
| quay.io/ | 6ba82beff18e | dompurify | 3.4.6 | 1 |
| quay.io/ | cb17600883a3 | dompurify | 3.4.6 | 1 |