CVE-2026-100370 Details
Description
DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.15, the isDangerousUrl() method is responsible for rejecting dangerous URL values in the href and xlink:href attributes. The weakness is that "javascript:" is rejected as a scheme, while "data:" is rejected only when the literal substring onload appears in the URL value (/^data:.*onload/i). Because data: payloads are routinely Base64-encoded, the dangerous content (<script>, event handlers, etc.) is invisible to that substring test. A URL such as data:text/html;base64,… therefore survives in href / xlink:href, even though the decoded payload is active markup. This is an incomplete input-validation / sanitization defect in the sanitizer itself. This issue has been patched in version 1.0.15.
A vulnerability exists in Rhukster DOMSanitizer versions prior to 1.0.15, specifically in the isDangerousUrl() method, which is designed to reject harmful URL schemes in href and xlink:href attributes. The issue arises because the method only rejects 'javascript:' URLs and applies a heuristic check for 'data:' URLs that looks for the substring 'onload'. This approach is flawed, as Base64-encoded data: URLs can bypass the check by hiding dangerous content, such as scripts or event handlers, from being detected. As a result, URLs like 'data:text/html;base64,...' can be processed without being sanitized, leading to the potential execution of active markup once decoded. This vulnerability stems from inadequate input validation and sanitization within the library.
Users should update to Rhukster DOMSanitizer version 1.0.15 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/rhukster/dom-sanitizer/security/advisories/GHSA-wcj2-r6vg-rm97 | CISA-ADP | AdvisoryRemedyVendor |
| https://github.com/rhukster/dom-sanitizer/commit/10f97807e4501d60f63987f2e76a38cdbf312dcb | [email protected] | Source CodeVendor |
| https://github.com/rhukster/dom-sanitizer/commit/fb8f758b41134fc5fb2f563666f2330c69e31f94 | [email protected] | Source CodeVendor |
| https://github.com/rhukster/dom-sanitizer/releases/tag/1.0.15 | [email protected] | Release NotesVendor |
| https://github.com/rhukster/dom-sanitizer/security/advisories/GHSA-wcj2-r6vg-rm97 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| DOMSanitizer | 1.0.14 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | New CVE Received | [email protected] |
| Sep 28, 2026 | CVE Modified | CISA-ADP |
Volerion