StackRadar

CVE-2026-49459

Medium

Advisory

Published 15 Jun 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
63
of 17,781 indexed, latest versions
Container images
56
deployed by those charts
Fix available
1 of 1
affected package

DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM

Carried by container images the latest versions of 63 of 17,781 indexed charts deploy, on 56 images.

Affected packageAffected versionsFixed inImages
dompurifynpm2.1.1, 2.2.6, 2.2.7, 2.3.1+25 more3.4.656
OSV records
GHSA-r47g-fvhr-h676

Charts affected

63 by stars
ChartLatestAffected imagesRadar Score
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-49459.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
dompurify@3.0.5
3.4.6

Open the chart page →

7,413
outlineschmitzis0.0.81 of 4See more

outline schmitzis 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-49459.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
dompurify@2.4.3
3.4.6

Open the chart page →

4,431
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-49459.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
dompurify@2.3.3
3.4.6

Open the chart page →

3,638
speckle-server-branch-hotfix-2.19.1speckleVerified publisher2.19.2-branch.hotfix-2.19.1.124125-665e7e11 of 5See more

speckle-server-branch-hotfix-2.19.1 speckle 2.19.2-branch.hotfix-2.19.1.124125-665e7e1

1 of the 5 container images this version deploys carry CVE-2026-49459.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.19.2-branch.hotfix-2.19.1.124125-665e7e14f9241665ae3
dompurify@3.0.11
3.4.6

Open the chart page →

16,368
speckle-server-branch-hotfix-2.20.2speckleVerified publisher2.20.3-branch.hotfix-2.20.2.149555-37ea0cb1 of 5See more

speckle-server-branch-hotfix-2.20.2 speckle 2.20.3-branch.hotfix-2.20.2.149555-37ea0cb

1 of the 5 container images this version deploys carry CVE-2026-49459.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.20.3-branch.hotfix-2.20.2.149555-37ea0cbfdc008effc7a
dompurify@3.0.11
3.4.6

Open the chart page →

16,400
speckle-server-branch-testing1speckleVerified publisher2.20.6-branch.testing1.154030-9b091141 of 5See more

speckle-server-branch-testing1 speckle 2.20.6-branch.testing1.154030-9b09114

1 of the 5 container images this version deploys carry CVE-2026-49459.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.20.6-branch.testing1.154030-9b0911432fc940d9b4c
dompurify@3.0.11
3.4.6

Open the chart page →

16,400
speckle-server-branch-testing4speckleVerified publisher2.20.2-branch.testing4.134160-9fad4b21 of 5See more

speckle-server-branch-testing4 speckle 2.20.2-branch.testing4.134160-9fad4b2

1 of the 5 container images this version deploys carry CVE-2026-49459.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.20.2-branch.testing4.134160-9fad4b210ad4ade8bf2
dompurify@3.0.11
3.4.6

Open the chart page →

16,019
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2026-49459.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.21.3-branch.testing5.219631-2153befd4ca6ebf09b9
dompurify@3.0.11
3.4.6

Open the chart page →

15,635
excalidashunxwaresVerified publisher2026.2.51 of 2See more

excalidash unxwares 2026.2.5

1 of the 2 container images this version deploys carry CVE-2026-49459.

Container imageDigestPackageFixed in
zimengxiong/excalidash-backend:0.4.271273af713c91
dompurify@3.3.0
3.4.6

Open the chart page →

2,620
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-49459.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
dompurify@3.2.4
3.4.6

Open the chart page →

5,484
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-49459.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
dompurify@3.3.1
3.4.6

Open the chart page →

5,459
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2026-49459.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
dompurify@2.1.1
3.4.6

Open the chart page →

5,806
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-49459.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
dompurify@2.5.6
3.4.6

Open the chart page →

9,381

Container images carrying it

56 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
dompurify@2.2.7
3.4.6
1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
dompurify@3.4.5
3.4.6
1
ghcr.io/seanmorley15/adventurelog-frontend:v0.13.051ee22428b41
dompurify@3.3.3
3.4.6
1
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
dompurify@3.4.0
3.4.6
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
dompurify@2.3.1
3.4.6
1
quay.io/wekan/wekan:v5.65cb17600883a3
dompurify@2.3.3
3.4.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.