Medium [CVE-2026-47423] Cross-site scripting vulnerability allows information disclosure
This medium-severity Red Hat Linux advisory covers CVE-2026-47423 affecting Red Hat Hardened Images, Red Hat Ceph Storage 9, Red Hat Openshift Data Foundation 4.
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedcontent by default, allowing browsers to re-clone an XSS payload after sanitization so that unsanitized markup inside is returned.
This issue is fixed in version 3.4.5. Due to the default allowance of `selectedcontent`, a remote attacker could craft a malicious payload that, after initial sanitization, could be re-cloned by browsers, leading to the execution of unsanitized markup.
This could result in information disclosure. User interaction is required for exploitation. * AC was raised from Low to High because exploitation requires specific browser support for the experimental HTML element, which is currently only available in Chromium 148+ and WebKit 625+.
No Red Hat product ships dompurify 3.4.4. Red Hat severity: Moderate — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N).
Weakness: CWE-79. Affected Red Hat products: Red Hat Hardened Images; Red Hat Ceph Storage 9; Red Hat Openshift Data Foundation 4.
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · high-confidence parse· fetched 6 days ago·verify at source
- 3.4.5
- ruff-main-0.15.11-1.hum1
- RHSA-2026:10999
Official advisory · high-confidence parse· fetched 6 days ago·verify at source
Mitigation checklist
- There is no direct mitigation for this flaw other than updating the DOMPurify library when upstream patches are available. As a defense-in-depth measure, Content Security Policy (CSP) headers that restrict inline script execution can help reduce the impact of XSS vulnerabilities. This issue is fixed in version 3.4.5.
Official advisory · high-confidence parse· fetched 6 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.