CVE-2025-26791

Publication date 14 February 2025

Last updated 19 February 2025


Ubuntu priority

DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).

Status

Package Ubuntu Release Status
node-dompurify 24.10 oracular
Needs evaluation
24.04 LTS noble
Needs evaluation
22.04 LTS jammy
Needs evaluation
20.04 LTS focal Not in release