Skip to content
VulniPulse
Medium5.9Red Hat Linux

Medium [CVE-2026-47423] Cross-site scripting vulnerability allows information disclosure

This medium-severity Red Hat Linux advisory covers CVE-2026-47423 affecting Red Hat Hardened Images, Red Hat Ceph Storage 9, Red Hat Openshift Data Foundation 4.

CVE-2026-47423 Published Jul 14, 2026Updated by vendor Jul 14, 2026
Affected products & platforms
Red Hat LinuxUnclassified
Open vendor advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedcontent by default, allowing browsers to re-clone an XSS payload after sanitization so that unsanitized markup inside is returned.

This issue is fixed in version 3.4.5. Due to the default allowance of `selectedcontent`, a remote attacker could craft a malicious payload that, after initial sanitization, could be re-cloned by browsers, leading to the execution of unsanitized markup.

This could result in information disclosure. User interaction is required for exploitation. * AC was raised from Low to High because exploitation requires specific browser support for the experimental HTML element, which is currently only available in Chromium 148+ and WebKit 625+.

No Red Hat product ships dompurify 3.4.4. Red Hat severity: Moderate — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N).

Weakness: CWE-79. Affected Red Hat products: Red Hat Hardened Images; Red Hat Ceph Storage 9; Red Hat Openshift Data Foundation 4.

Affected versions

No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.

Official advisory · high-confidence parse· fetched 6 days ago·verify at source

Fixed versions
  • 3.4.5
  • ruff-main-0.15.11-1.hum1
  • RHSA-2026:10999

Official advisory · high-confidence parse· fetched 6 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • There is no direct mitigation for this flaw other than updating the DOMPurify library when upstream patches are available. As a defense-in-depth measure, Content Security Policy (CSP) headers that restrict inline script execution can help reduce the impact of XSS vulnerabilities. This issue is fixed in version 3.4.5.

Official advisory · high-confidence parse· fetched 6 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.