- by x32x01 ||
3 New CVEs in PHP DOMSanitizer: URL Sanitization and XSS Issues
I previously shared research about a vulnerability I discovered in
At the time, the CVE was still in the requested stage. After continuing the research, I identified two additional vulnerabilities in the project.
The result is three officially published CVEs affecting DOMSanitizer. The issues have now been disclosed publicly, and fixes have been released.
Because sanitization is often used as a security boundary, weaknesses in URL validation can become important security issues, especially when attacker-controlled content reaches attributes such as
The issue was caused by an incomplete blacklist in the URL validation logic, allowing certain malicious URL patterns to bypass the sanitizer.
Versions up to
Under certain conditions, attacker-controlled URLs could bypass the validation logic, creating a potential cross-site scripting (XSS) issue.
The affected versions are up to
The sanitizer checked for dangerous content using a pattern that could detect certain literal strings, but Base64-encoded payloads could hide the dangerous content from that check.
As a result, certain Base64-encoded
This issue affects versions before 1.0.15 and was fixed in version
For projects using an affected version, upgrading to DOMSanitizer 1.0.16 or later is the safest way to address all three issues.
That makes URL validation particularly important. Blocking only known dangerous patterns is not always enough because attackers can represent the same payload in different forms.
The three CVEs highlight several common problems in sanitizer design:
The recommended target is:
DOMSanitizer 1.0.16 or later
This is especially important for applications that process user-controlled HTML, SVG, MathML, or URLs.
https://www.cve.org/CVERecord?id=CVE-2026-103687
CVE-2026-103686
https://www.cve.org/CVERecord?id=CVE-2026-103686
CVE-2026-100370
https://www.cve.org/CVERecord?id=CVE-2026-100370
The three vulnerabilities are now publicly disclosed, and the corresponding fixes have been released.
If you maintain a project that depends on DOMSanitizer, upgrading to a fixed version should be part of your security update process.
I previously shared research about a vulnerability I discovered in
rhukster/dom-sanitizer, a PHP sanitization library designed to handle HTML, SVG, and MathML content.At the time, the CVE was still in the requested stage. After continuing the research, I identified two additional vulnerabilities in the project.
The result is three officially published CVEs affecting DOMSanitizer. The issues have now been disclosed publicly, and fixes have been released.
What Is DOMSanitizer?
DOMSanitizer is a PHP library used to sanitize potentially unsafe DOM content, including HTML, SVG, and MathML.Because sanitization is often used as a security boundary, weaknesses in URL validation can become important security issues, especially when attacker-controlled content reaches attributes such as
href and xlink:href.The Three Published CVEs
Here are the three vulnerabilities identified in the project:CVE-2026-103687 - SVG URL Sanitization Bypass
This vulnerability affects the URL handling logic used during SVG sanitization.The issue was caused by an incomplete blacklist in the URL validation logic, allowing certain malicious URL patterns to bypass the sanitizer.
Versions up to
1.0.15 are affected, and the issue is fixed in 1.0.16.CVE-2026-103686 - XSS via isDangerousUrl()
This vulnerability affectsDOMSanitizer::isDangerousUrl(), the function responsible for identifying dangerous URLs.Under certain conditions, attacker-controlled URLs could bypass the validation logic, creating a potential cross-site scripting (XSS) issue.
The affected versions are up to
1.0.15, with the vulnerability fixed in 1.0.16.CVE-2026-100370 - Incomplete data: URL Sanitization
The third vulnerability involves the handling ofdata: URLs.The sanitizer checked for dangerous content using a pattern that could detect certain literal strings, but Base64-encoded payloads could hide the dangerous content from that check.
As a result, certain Base64-encoded
data: URLs could bypass validation when used in attributes such as href and xlink:hrefThis issue affects versions before 1.0.15 and was fixed in version
1.0.15.Affected Versions and Fixes
| CVE | Issue | Affected Version | Fixed Version |
|---|---|---|---|
| CVE-2026-103687 | SVG URL sanitization bypass | ≤ 1.0.15 | 1.0.16 |
| CVE-2026-103686 | XSS through URL validation | ≤ 1.0.15 | 1.0.16 |
| CVE-2026-100370 | Base64-encoded data URL bypass | < 1.0.15 | 1.0.15 |
Why These Vulnerabilities Matter
HTML and SVG sanitizers are commonly placed between untrusted input and a web application's output.That makes URL validation particularly important. Blocking only known dangerous patterns is not always enough because attackers can represent the same payload in different forms.
The three CVEs highlight several common problems in sanitizer design:
- Incomplete URL blacklists can leave unexpected bypasses.
- URL validation needs to account for different URL schemes and representations.
- Base64 encoding can hide dangerous content from simple string-based checks.
- Sanitization logic should be treated as security-sensitive code.
Recommended Action
If your PHP application usesrhukster/dom-sanitizer, check the installed version and upgrade it if it is affected.The recommended target is:
DOMSanitizer 1.0.16 or later
This is especially important for applications that process user-controlled HTML, SVG, MathML, or URLs.
CVE References
CVE-2026-103687https://www.cve.org/CVERecord?id=CVE-2026-103687
CVE-2026-103686
https://www.cve.org/CVERecord?id=CVE-2026-103686
CVE-2026-100370
https://www.cve.org/CVERecord?id=CVE-2026-100370
The three vulnerabilities are now publicly disclosed, and the corresponding fixes have been released.
If you maintain a project that depends on DOMSanitizer, upgrading to a fixed version should be part of your security update process.
Last edited: