Post #980694
2026-03-05 13:15 UTC
DOMPurify 2.5.9 and DOMPurify 3.3.2 were released today in a rush to fix a security issue caused by jsdom's faulty tag parsing.
A total of four people reported the exacty same bug within a window of three days.
One did so via email, thank you. One did so via private security advisory, thank you too.
One however simply published a ticket for everyone to see, the other one just dropped a CVE on us without a working fix release. Thanks for nothing.
https://github.com/cure53/DOMPurify/releases/tag/3.3.2
https://github.com/cure53/DOMPurify/releases/tag/2.5.9
Replies (1)
-
@addison@nothing-ever.works 2026-03-05 17:21
@cure53@infosec.exchange @vulncheck@infosec.exchange What happened here? Y'all are normally pretty good about issuing CVEs