CVE-2026-66010

DOMPurify before 3.4.12 Hook Bypass via CUSTOM_ELEMENT_HANDLING

DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attributes on custom elements that later re-inject them into innerHTML sinks, creating second-order XSS gadgets.


We have discovered 63,663 live websites that are affected by CVE-2026-66010.

Run a Free Instant Scan




Affected Software

Product  DOMPurify
Category JavaScript Libraries
Vulnerable Domains63,663 live websites (100% of DOMPurify install base)
Vulnerable Versions
  • from 0 through 3.4.12
Vulnerable Versions Count71 versions ( 100% of all versions)



Details

  • Published - Jul 24, 2026
  • Updated - Jul 24, 2026

Credits

  • Rikuxx0 (reporter)

Website Distribution by Country

Number of websites using CVE-2026-66010
United States17,537 websites



Germany8,640 websites
France3,898 websites
Japan2,889 websites
GB2,598 websites
Netherlands2,443 websites
Brazil2,181 websites
Italy1,994 websites
Poland1,841 websites
Switzerland1,558 websites

Website Distribution by TLD

Number of websites using CVE-2026-66010
.com24,260 websites
.de6,008 websites
.org2,874 websites
.nl2,193 websites
.com.br2,025 websites
.fr1,808 websites
.co.uk1,533 websites
.it1,454 websites
.net1,417 websites
.pl1,397 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-66010

Top websites that are affected by CVE-2026-66010. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.*****.com United States*,***
*****.*********.com United States*,***
********.org United States*,***
***********.ch Switzerland*,***
*****.com United States*,***
********.org United States*,***
***********.dk Denmark*,***
************.org France*,***
*********.com United States*,***
*************.com United States*,***
See full domain list

FAQ

A total of 63,663 websites have been identified as vulnerable to CVE-2026-66010, based on global website indexing conducted by WebTechSurvey.
The DOMPurify is affected by the CVE-2026-66010 vulnerability.
DOMPurify versions up to 3.4.12 are vulnerable to CVE-2026-66010.
CVE-2026-66010 is resolved in version 3.4.12 of DOMPurify.