Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100370— DOMSanitizer - Incomplete data: URL Sanitization in DOMSanitizer::isDangerousUrl() Allows Base64-Encoded Payloads to Bypass href and xlink:href Validation

Quick assessment

Affected
rhukster dom-sanitizer
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

DOMSanitizer 是用于 PHP 7.3+ 的 DOM/SVG/MathML 内容安全库。在 1.0.15 版本之前, 方法负责拒绝 和 属性中存在危险的 URL 值。该实现的弱点在于:虽然对 方案进行了拒绝,但对 方案仅在 URL 值中包含字面量子字符串 时才进行拒绝(即使用正则表达式 进行匹配)。由于 载荷通常采用 Base64 编码,危险内容(如 标签、事件处理器等)在原始 URL 中不可见,因此无法通过该子字符串匹配检测出来。因此,类似 这样的 URL 即使在其解码后的载荷包含活跃标记(active

CVSS 4.7 · Medium

Possible ATT&CK Techniques 1 AI

T1059 · Command and Scripting Interpreter
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100370

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
DOMSanitizer - Incomplete data: URL Sanitization in DOMSanitizer::isDangerousUrl() Allows Base64-Encoded Payloads to Bypass href and xlink:href Validation
Source: CVE Program / CVE List V5
Vulnerability Description
DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.15, the isDangerousUrl() method is responsible for rejecting dangerous URL values in the href and xlink:href attributes. The weakness is that "javascript:" is rejected as a scheme, while "data:" is rejected only when the literal substring onload appears in the URL value (/^data:.*onload/i). Because data: payloads are routinely Base64-encoded, the dangerous content (<script>, event handlers, etc.) is invisible to that substring test. A URL such as data:text/html;base64,… therefore survives in href / xlink:href, even though the decoded payload is active markup. This is an incomplete input-validation / sanitization defect in the sanitizer itself. This issue has been patched in version 1.0.15.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
输入验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
rhukster dom-sanitizer < 1.0.15 -

II. Public POCs for CVE-2026-100370

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100370

请登录查看更多情报信息。

Other References for CVE-2026-100370 (4)

IV. Related Vulnerabilities

V. Comments for CVE-2026-100370

No comments yet


Leave a comment