CVE-2026-49459
MediumAdvisory
Published 15 Jun 2026In the index since 6 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.1
- base score, highest
- EPSS
- 0.004
- 30th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 63
- of 17,781 indexed, latest versions
- Container images
- 56
- deployed by those charts
- Fix available
- 1 of 1
- affected package
DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM
Carried by container images the latest versions of 63 of 17,781 indexed charts deploy, on 56 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| dompurifynpm | 2.1.1, 2.2.6, 2.2.7, 2.3.1+25 more | 3.4.6 | 56 |
- OSV records
- GHSA-r47g-fvhr-h676
Charts affected
63 by stars
Container images carrying it
56 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.