Description
DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.15, the isDangerousUrl() method is responsible for rejecting dangerous URL values in the href and xlink:href attributes. The weakness is that "javascript:" is rejected as a scheme, while "data:" is rejected only when the literal substring onload appears in the URL value (/^data:.*onload/i). Because data: payloads are routinely Base64-encoded, the dangerous content (<script>, event handlers, etc.) is invisible to that substring test. A URL such as data:text/html;base64,… therefore survives in href / xlink:href, even though the decoded payload is active markup. This is an incomplete input-validation / sanitization defect in the sanitizer itself. This issue has been patched in version 1.0.15.
Published: 2026-09-28
Score: 4.7 Medium
EPSS: n/a
KEV: No
Impact: Cross‑site scripting via data URLs
Action: Apply patch
AI Analysis

Impact

DOMSanitizer performs input validation against href and xlink:href attributes, but its isDangerousUrl() function mistakenly allows data: URLs that are Base64‑encoded to bypass the onload substring check. Because the malicious payload inside the data URL is hidden until decoded, the sanitization fails and the contained script or event handler can execute, leading to a cross‑site scripting vulnerability.

Affected Systems

The vulnerability affects the rhukster:dom‑sanitizer package, specifically all versions prior to 1.0.15. The library is used in PHP applications that sanitize DOM, SVG, or MathML content.

Risk and Exploitability

The CVSS score of 4.7 indicates moderate severity; the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited known exploitation. Based on the description, the likely attack vector involves an attacker feeding crafted link attributes into the sanitizer, which is a local or remote injection depending on how the library is used. The weakness is an input‑validation flaw (CWE‑20).

Generated by OpenCVE AI on September 28, 2026 at 21:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade rhukster:dom‑sanitizer to version 1.0.15 or newer, which removes the permissive data: URL check.
  • If upgrading is not possible, configure the application to reject all data: URLs before they reach the sanitizer or de‑code and validate them explicitly.
  • Add an additional layer of input validation in your code that ensures no data: URLs contain untrusted or executable content before passing values to the library.

Generated by OpenCVE AI on September 28, 2026 at 21:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.15, the isDangerousUrl() method is responsible for rejecting dangerous URL values in the href and xlink:href attributes. The weakness is that "javascript:" is rejected as a scheme, while "data:" is rejected only when the literal substring onload appears in the URL value (/^data:.*onload/i). Because data: payloads are routinely Base64-encoded, the dangerous content (<script>, event handlers, etc.) is invisible to that substring test. A URL such as data:text/html;base64,… therefore survives in href / xlink:href, even though the decoded payload is active markup. This is an incomplete input-validation / sanitization defect in the sanitizer itself. This issue has been patched in version 1.0.15.
Title DOMSanitizer - Incomplete data: URL Sanitization in DOMSanitizer::isDangerousUrl() Allows Base64-Encoded Payloads to Bypass href and xlink:href Validation
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-28T20:40:03.613Z

Reserved: 2026-09-25T19:19:54.699Z

Link: CVE-2026-100370

cve-icon Vulnrichment

Updated: 2026-09-28T20:39:43.065Z

cve-icon NVD

Status : Received

Published: 2026-09-28T21:17:10.280

Modified: 2026-09-28T21:17:10.280

Link: CVE-2026-100370

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T21:30:07Z

Weaknesses
  • CWE-20

    Improper Input Validation