Vulnerability Description
DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.10, DOMSanitizer::sanitize() allows <style> elements in SVG content but never inspects their text content. CSS url() references and @import rules pass through unfiltered, causing the browser to issue HTTP requests to attacker-controlled hosts when the sanitized SVG is rendered. Version 1.0.10 fixes the issue.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/rhukster/dom-sanitizer/commit/49a98046b708a4c92f754f5b0ef1720
- https://github.com/rhukster/dom-sanitizer/releases/tag/1.0.10
- https://github.com/rhukster/dom-sanitizer/security/advisories/GHSA-93vf-569f-22c
FAQ
What is CVE-2026-40301?
CVE-2026-40301 is a vulnerability with a CVSS score of 4.7 (MEDIUM). DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.10, DOMSanitizer::sanitize() allows <style> elements in SVG content but never inspects their text content. CSS url() refer...
How severe is CVE-2026-40301?
CVE-2026-40301 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-40301?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.