Skip to main content
Loading…
    CVE-2026-41240 — DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions prior to 3.4.0 have an inconsistency between FORBID_TAGS and FORBID_ATTR handling when function-based ADD_TAG — CVE Database · The Intelligence Room