CVE-2026-100370
Received Received - Intake

DOM-based XSS via data: URL in DOMSanitizer

Vulnerability report for CVE-2026-100370, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: GitHub, Inc.

Description

DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.15, the isDangerousUrl() method is responsible for rejecting dangerous URL values in the href and xlink:href attributes. The weakness is that "javascript:" is rejected as a scheme, while "data:" is rejected only when the literal substring onload appears in the URL value (/^data:.*onload/i). Because data: payloads are routinely Base64-encoded, the dangerous content (<script>, event handlers, etc.) is invisible to that substring test. A URL such as data:text/html;base64,… therefore survives in href / xlink:href, even though the decoded payload is active markup. This is an incomplete input-validation / sanitization defect in the sanitizer itself. This issue has been patched in version 1.0.15.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects DOMSanitizer, a DOM/SVG/MathML Sanitizer for PHP 7.3+. The issue is in the isDangerousUrl() method which incorrectly rejects dangerous URL schemes. While 'javascript:' is blocked, 'data:' URLs are only blocked if they contain the substring 'onload'. Attackers can bypass this by Base64-encoding malicious payloads in 'data:' URLs, allowing active markup like scripts to execute when decoded.

Detection Guidance

Check if your system uses DOMSanitizer version 1.0.15 or earlier. Inspect href and xlink:href attributes in HTML/SVG/MathML content for data:text/html;base64 URLs that may contain malicious payloads. Use tools like grep or custom scripts to scan for suspicious data URIs.

Impact Analysis

This vulnerability could allow attackers to inject malicious scripts or content into web pages via crafted 'data:' URLs. If your application uses DOMSanitizer before version 1.0.15, users might be exposed to cross-site scripting (XSS) attacks when interacting with sanitized content. The impact depends on how the sanitizer is used in your specific application.

Compliance Impact

This vulnerability could potentially violate compliance with standards like GDPR and HIPAA by allowing malicious data: URLs to bypass sanitization, enabling execution of arbitrary scripts or event handlers in contexts where user input should be sanitized. This could lead to unauthorized data access or manipulation, undermining data protection requirements.

Mitigation Strategies

Upgrade DOMSanitizer to version 1.0.15 or later. Review and sanitize all user-provided URLs, especially those using data: schemes. Implement additional input validation to block dangerous payloads in URLs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100370. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart