{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "extracted_events": [
              {
                "introduced": "0"
              },
              {
                "fixed": "1.0.15"
              }
            ],
            "source": [
              "AFFECTED_FIELD",
              "REFERENCES"
            ]
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "10f97807e4501d60f63987f2e76a38cdbf312dcb"
            },
            {
              "fixed": "fb8f758b41134fc5fb2f563666f2330c69e31f94"
            }
          ],
          "repo": "https://github.com/rhukster/dom-sanitizer",
          "type": "GIT"
        }
      ]
    }
  ],
  "aliases": [
    "GHSA-wcj2-r6vg-rm97"
  ],
  "database_specific": {
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
      "CWE-20"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-100370.json"
  },
  "details": "DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.15, the isDangerousUrl() method is responsible for rejecting dangerous URL values in the href and xlink:href attributes. The weakness is that \"javascript:\" is rejected as a scheme, while \"data:\" is rejected only when the literal substring onload appears in the URL value (/^data:.*onload/i). Because data: payloads are routinely Base64-encoded, the dangerous content (\u003cscript\u003e, event handlers, etc.) is invisible to that substring test. A URL such as data:text/html;base64,… therefore survives in href / xlink:href, even though the decoded payload is active markup. This is an incomplete input-validation / sanitization defect in the sanitizer itself. This issue has been patched in version 1.0.15.",
  "id": "CVE-2026-100370",
  "modified": "2026-09-30T03:30:19.385820183Z",
  "published": "2026-09-28T20:07:09.470Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/rhukster/dom-sanitizer/releases/tag/1.0.15"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-100370.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/rhukster/dom-sanitizer/security/advisories/GHSA-wcj2-r6vg-rm97"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-100370"
    },
    {
      "type": "FIX",
      "url": "https://github.com/rhukster/dom-sanitizer/commit/10f97807e4501d60f63987f2e76a38cdbf312dcb"
    },
    {
      "type": "FIX",
      "url": "https://github.com/rhukster/dom-sanitizer/commit/fb8f758b41134fc5fb2f563666f2330c69e31f94"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "DOMSanitizer - Incomplete data: URL Sanitization in DOMSanitizer::isDangerousUrl() Allows Base64-Encoded Payloads to Bypass href and xlink:href Validation"
}