In DOMPurify through 3.3.3, function predicates supplied via ADD_ATTR or ADD_TAGS to DOMPurify.sanitize() persist in internal state (EXTRA_ELEMENT_HANDLING) across subsequent sanitize() calls on the same instance. If a later call on the same instance provides ADD_ATTR or ADD_TAGS as an array rather than a function, the previously set function handler is neither cleared nor overwritten, so it continues to approve attacker-controlled attributes or tags. This can allow dangerous event-handler attributes or forbidden tags (bypassing FORBID_TAGS) to survive sanitization, resulting in cross-site scripting. The vendor (Cure53) considers this an edge case outside DOMPurify's threat model; the referenced advisory lists 3.4.0 as the patched version.
We have discovered 63,423 live websites that are affected by CVE-2026-65911.
| Product | |
| Category | JavaScript Libraries |
| Vulnerable Domains | 63,423 live websites (100% of DOMPurify install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 62 versions ( 87% of all versions) |
| 17,360 websites | |
| 8,629 websites | |
| 3,896 websites | |
| 2,889 websites | |
| 2,595 websites | |
| 2,439 websites | |
| 2,175 websites | |
| 1,992 websites | |
| 1,841 websites | |
| 1,558 websites |
| .com | 24,139 websites |
| .de | 6,004 websites |
| .org | 2,817 websites |
| .nl | 2,187 websites |
| .com.br | 2,019 websites |
| .fr | 1,808 websites |
| .co.uk | 1,531 websites |
| .it | 1,453 websites |
| .net | 1,414 websites |
| .pl | 1,397 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.*****.com | *,*** | ||
| ********.org | *,*** | ||
| ***********.ch | *,*** | ||
| *****.com | *,*** | ||
| ********.org | *,*** | ||
| ***********.dk | *,*** | ||
| ************.org | *,*** | ||
| *********.com | *,*** | ||
| *************.com | *,*** | ||
| *****************.org | **,*** |
FAQ