3 New CVEs in PHP DOMSanitizer

x32x01
  • by x32x01 ||
3 New CVEs in PHP DOMSanitizer: URL Sanitization and XSS Issues
I previously shared research about a vulnerability I discovered in rhukster/dom-sanitizer, a PHP sanitization library designed to handle HTML, SVG, and MathML content.
At the time, the CVE was still in the requested stage. After continuing the research, I identified two additional vulnerabilities in the project.
The result is three officially published CVEs affecting DOMSanitizer. The issues have now been disclosed publicly, and fixes have been released.



What Is DOMSanitizer?​

DOMSanitizer is a PHP library used to sanitize potentially unsafe DOM content, including HTML, SVG, and MathML.
Because sanitization is often used as a security boundary, weaknesses in URL validation can become important security issues, especially when attacker-controlled content reaches attributes such as href and xlink:href.



The Three Published CVEs​

Here are the three vulnerabilities identified in the project:

CVE-2026-103687 - SVG URL Sanitization Bypass​

This vulnerability affects the URL handling logic used during SVG sanitization.
The issue was caused by an incomplete blacklist in the URL validation logic, allowing certain malicious URL patterns to bypass the sanitizer.
Versions up to 1.0.15 are affected, and the issue is fixed in 1.0.16.

CVE-2026-103686 - XSS via isDangerousUrl()​

This vulnerability affects DOMSanitizer::isDangerousUrl(), the function responsible for identifying dangerous URLs.
Under certain conditions, attacker-controlled URLs could bypass the validation logic, creating a potential cross-site scripting (XSS) issue.
The affected versions are up to 1.0.15, with the vulnerability fixed in 1.0.16.

CVE-2026-100370 - Incomplete data: URL Sanitization​

The third vulnerability involves the handling of data: URLs.
The sanitizer checked for dangerous content using a pattern that could detect certain literal strings, but Base64-encoded payloads could hide the dangerous content from that check.
As a result, certain Base64-encoded data: URLs could bypass validation when used in attributes such as href and xlink:href
This issue affects versions before 1.0.15 and was fixed in version 1.0.15.



Affected Versions and Fixes​

CVEIssueAffected VersionFixed Version
CVE-2026-103687SVG URL sanitization bypass≤ 1.0.151.0.16
CVE-2026-103686XSS through URL validation≤ 1.0.151.0.16
CVE-2026-100370Base64-encoded data URL bypass< 1.0.151.0.15
For projects using an affected version, upgrading to DOMSanitizer 1.0.16 or later is the safest way to address all three issues.



Why These Vulnerabilities Matter​

HTML and SVG sanitizers are commonly placed between untrusted input and a web application's output.
That makes URL validation particularly important. Blocking only known dangerous patterns is not always enough because attackers can represent the same payload in different forms.
The three CVEs highlight several common problems in sanitizer design:
  • Incomplete URL blacklists can leave unexpected bypasses.
  • URL validation needs to account for different URL schemes and representations.
  • Base64 encoding can hide dangerous content from simple string-based checks.
  • Sanitization logic should be treated as security-sensitive code.



Recommended Action​

If your PHP application uses rhukster/dom-sanitizer, check the installed version and upgrade it if it is affected.
The recommended target is:
DOMSanitizer 1.0.16 or later
This is especially important for applications that process user-controlled HTML, SVG, MathML, or URLs.



CVE References​

CVE-2026-103687
https://www.cve.org/CVERecord?id=CVE-2026-103687
CVE-2026-103686
https://www.cve.org/CVERecord?id=CVE-2026-103686
CVE-2026-100370
https://www.cve.org/CVERecord?id=CVE-2026-100370
The three vulnerabilities are now publicly disclosed, and the corresponding fixes have been released.
If you maintain a project that depends on DOMSanitizer, upgrading to a fixed version should be part of your security update process.
 
Last edited:
Similar threads
x32x01
Replies
0
Views
25
x32x01
x32x01
x32x01
Replies
0
Views
42
x32x01
x32x01
x32x01
Replies
0
Views
97
x32x01
x32x01
x32x01
Replies
0
Views
130
x32x01
x32x01
x32x01
Replies
0
Views
65
x32x01
x32x01
Forum Statistics
Threads
1,137
Messages
1,143
Members
16
Latest Member
b_a_s_m_a_l_a7
Back
Top