sanitize-html: `sanitize-html`: Stored Cross-Site Scripting via HTML sanitizer bypass

zetlyn/cve-redhat vulnerability cve CVE-2026-44990 known 2026-06-12

https://access.redhat.com/security/cve/CVE-2026-44990

Properties

cvss8.1
receipt
Source
Red Hat
Its words
8.1
Read by
field:cvss3_score
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-44990",
  "CWE": "CWE-79",
  "advisories": [
    "RHSA-2026:51349",
    "RHSA-2026:36883",
    "RHSA-2026:70267",
    "RHSA-2026:63046",
    "RHSA-2026:57194",
    "RHSA-2026:59593",
    "RHSA-2026:47737",
    "RHSA-2026:42146",
    "RHSA-2026:46903",
    "RHSA-2026:63103",
    "RHSA-2026:41055",
    "RHSA-2026:40262",
    "RHSA-2026:41031",
    "RHSA-2026:46685",
    "RHSA-2026:46885",
    "RHSA-2026:47735",
    "RHSA-2026:57191",
    "RHSA-2026:48124",
    "RHSA-2026:43052",
    "RHSA-2026:51197",
    "RHSA-2026:47451",
    "RHSA-2026:51196",
    "RHSA-2026:66371",
    "RHSA-2026:42796",
    "RHSA-2026:36882",
    "RHSA-2026:60386",
    "RHSA-2026:60441",
    "RHSA-2026:41066",
    "RHSA-2026:41064",
    "RHSA-2026:47388",
    "RHSA-2026:46598",
    "RHSA-2026:67936"
  ],
  "affected_packages": [
    "quay/quay-rhel8:1788593843",
    "satellite/iop-vulnerability-frontend-rhel9:1785937325",
    "rhacm2/console-rhel9:1786908361",
    "quay/quay-rhel8:1784353904",
    "quay/quay-rhel9:1783955846",
    "quay/quay-rhel8:1784351966",
    "openshift4/ose-console-rhel9:1789453727",
    "openshift4/ose-console-rhel9:1788359934",
    "container-native-virtualization/kubevirt-console-plugin-rhel9:1784629964",
    "multicluster-engine/console-mce-rhel9:1786911977",
    "multicluster-engine/console-mce-rhel9:1783348181",
    "multicluster-engine/console-mce-rhel9:1785078604",
    "multicluster-engine/console-mce-rhel9:1786668856",
    "multicluster-engine/console-mce-rhel9:1783351002",
    "quay/quay-rhel8:1783750447",
    "quay/quay-rhel8:1784125838",
    "rhacm2/console-rhel9:1784578812",
    "multicluster-engine/console-mce-rhel9:1784312384",
    "devspaces/dashboard-rhel9:1784737150",
    "openshift4/ose-console-rhel9:1788573287",
    "rhacm2/console-rhel9:1783350952",
    "rhacm2/console-rhel9:1783451729",
    "container-native-virtualization/kubevirt-console-plugin-rhel9:1784844382",
    "satellite/iop-host-inventory-frontend-rhel9:1785922764",
    "satellite/iop-host-inventory-frontend-rhel9:1785956497",
    "rhacm2/console-rhel9:1787335105",
    "rhacm2/console-rhel9:1785078581",
    "openshift4/ose-console-rhel9:1788350963",
    "quay/quay-rhel8:1783751865",
    "openshift4/ose-console-rhel9:1787746382"
  ],
  "bugzilla": "2488565",
  "bugzilla_description": "sanitize-html: `sanitize-html`: Stored Cross-Site Scripting via HTML sanitizer bypass",
  "cvss3_score": "8.1",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-06-12T20:39:47Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-44990.json",
  "severity": "important"
}
cweCWE-79
receipt
Source
Red Hat
Its words
CWE-79
Read by
field:CWE
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-44990",
  "CWE": "CWE-79",
  "advisories": [
    "RHSA-2026:51349",
    "RHSA-2026:36883",
    "RHSA-2026:70267",
    "RHSA-2026:63046",
    "RHSA-2026:57194",
    "RHSA-2026:59593",
    "RHSA-2026:47737",
    "RHSA-2026:42146",
    "RHSA-2026:46903",
    "RHSA-2026:63103",
    "RHSA-2026:41055",
    "RHSA-2026:40262",
    "RHSA-2026:41031",
    "RHSA-2026:46685",
    "RHSA-2026:46885",
    "RHSA-2026:47735",
    "RHSA-2026:57191",
    "RHSA-2026:48124",
    "RHSA-2026:43052",
    "RHSA-2026:51197",
    "RHSA-2026:47451",
    "RHSA-2026:51196",
    "RHSA-2026:66371",
    "RHSA-2026:42796",
    "RHSA-2026:36882",
    "RHSA-2026:60386",
    "RHSA-2026:60441",
    "RHSA-2026:41066",
    "RHSA-2026:41064",
    "RHSA-2026:47388",
    "RHSA-2026:46598",
    "RHSA-2026:67936"
  ],
  "affected_packages": [
    "quay/quay-rhel8:1788593843",
    "satellite/iop-vulnerability-frontend-rhel9:1785937325",
    "rhacm2/console-rhel9:1786908361",
    "quay/quay-rhel8:1784353904",
    "quay/quay-rhel9:1783955846",
    "quay/quay-rhel8:1784351966",
    "openshift4/ose-console-rhel9:1789453727",
    "openshift4/ose-console-rhel9:1788359934",
    "container-native-virtualization/kubevirt-console-plugin-rhel9:1784629964",
    "multicluster-engine/console-mce-rhel9:1786911977",
    "multicluster-engine/console-mce-rhel9:1783348181",
    "multicluster-engine/console-mce-rhel9:1785078604",
    "multicluster-engine/console-mce-rhel9:1786668856",
    "multicluster-engine/console-mce-rhel9:1783351002",
    "quay/quay-rhel8:1783750447",
    "quay/quay-rhel8:1784125838",
    "rhacm2/console-rhel9:1784578812",
    "multicluster-engine/console-mce-rhel9:1784312384",
    "devspaces/dashboard-rhel9:1784737150",
    "openshift4/ose-console-rhel9:1788573287",
    "rhacm2/console-rhel9:1783350952",
    "rhacm2/console-rhel9:1783451729",
    "container-native-virtualization/kubevirt-console-plugin-rhel9:1784844382",
    "satellite/iop-host-inventory-frontend-rhel9:1785922764",
    "satellite/iop-host-inventory-frontend-rhel9:1785956497",
    "rhacm2/console-rhel9:1787335105",
    "rhacm2/console-rhel9:1785078581",
    "openshift4/ose-console-rhel9:1788350963",
    "quay/quay-rhel8:1783751865",
    "openshift4/ose-console-rhel9:1787746382"
  ],
  "bugzilla": "2488565",
  "bugzilla_description": "sanitize-html: `sanitize-html`: Stored Cross-Site Scripting via HTML sanitizer bypass",
  "cvss3_score": "8.1",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-06-12T20:39:47Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-44990.json",
  "severity": "important"
}
packagesquay/quay-rhel8:1788593843, satellite/iop-vulnerability-frontend-rhel9:1785937325, rhacm2/console-rhel9:1786908361, quay/quay-rhel8:1784353904, quay/quay-rhel9:1783955846, quay/quay-rhel8:1784351966, openshift4/ose-console-rhel9:1789453727, openshift4/ose-console-rhel9:1788359934, container-native-virtualization/kubevirt-console-plugin-rhel9:1784629964, multicluster-engine/console-mce-rhel9:1786911977, multicluster-engine/console-mce-rhel9:1783348181, multicluster-engine/console-mce-rhel9:1785078604, multicluster-engine/console-mce-rhel9:1786668856, multicluster-engine/console-mce-rhel9:1783351002, quay/quay-rhel8:1783750447, quay/quay-rhel8:1784125838, rhacm2/console-rhel9:1784578812, multicluster-engine/console-mce-rhel9:1784312384, devspaces/dashboard-rhel9:1784737150, openshift4/ose-console-rhel9:1788573287, rhacm2/console-rhel9:1783350952, rhacm2/console-rhel9:1783451729, container-native-virtualization/kubevirt-console-plugin-rhel9:1784844382, satellite/iop-host-inventory-frontend-rhel9:1785922764, satellite/iop-host-inventory-frontend-rhel9:1785956497, rhacm2/console-rhel9:1787335105, rhacm2/console-rhel9:1785078581, openshift4/ose-console-rhel9:1788350963, quay/quay-rhel8:1783751865, openshift4/ose-console-rhel9:1787746382
receipt
Source
Red Hat
Its words
quay/quay-rhel8:1788593843, satellite/iop-vulnerability-frontend-rhel9:1785937325, rhacm2/console-rhel9:1786908361, quay/quay-rhel8:1784353904, quay/quay-rhel9:1783955846, quay/quay-rhel8:1784351966, openshift4/ose-console-rhel9:1789453727, openshift4/ose-console-rhel9:1788359934, container-native-virtualization/kubevirt-console-plugin-rhel9:1784629964, multicluster-engine/console-mce-rhel9:1786911977, multicluster-engine/console-mce-rhel9:1783348181, multicluster-engine/console-mce-rhel9:1785078604, multicluster-engine/console-mce-rhel9:1786668856, multicluster-engine/console-mce-rhel9:1783351002, quay/quay-rhel8:1783750447, quay/quay-rhel8:1784125838, rhacm2/console-rhel9:1784578812, multicluster-engine/console-mce-rhel9:1784312384, devspaces/dashboard-rhel9:1784737150, openshift4/ose-console-rhel9:1788573287, rhacm2/console-rhel9:1783350952, rhacm2/console-rhel9:1783451729, container-native-virtualization/kubevirt-console-plugin-rhel9:1784844382, satellite/iop-host-inventory-frontend-rhel9:1785922764, satellite/iop-host-inventory-frontend-rhel9:1785956497, rhacm2/console-rhel9:1787335105, rhacm2/console-rhel9:1785078581, openshift4/ose-console-rhel9:1788350963, quay/quay-rhel8:1783751865, openshift4/ose-console-rhel9:1787746382
Read by
field:affected_packages[]
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-44990",
  "CWE": "CWE-79",
  "advisories": [
    "RHSA-2026:51349",
    "RHSA-2026:36883",
    "RHSA-2026:70267",
    "RHSA-2026:63046",
    "RHSA-2026:57194",
    "RHSA-2026:59593",
    "RHSA-2026:47737",
    "RHSA-2026:42146",
    "RHSA-2026:46903",
    "RHSA-2026:63103",
    "RHSA-2026:41055",
    "RHSA-2026:40262",
    "RHSA-2026:41031",
    "RHSA-2026:46685",
    "RHSA-2026:46885",
    "RHSA-2026:47735",
    "RHSA-2026:57191",
    "RHSA-2026:48124",
    "RHSA-2026:43052",
    "RHSA-2026:51197",
    "RHSA-2026:47451",
    "RHSA-2026:51196",
    "RHSA-2026:66371",
    "RHSA-2026:42796",
    "RHSA-2026:36882",
    "RHSA-2026:60386",
    "RHSA-2026:60441",
    "RHSA-2026:41066",
    "RHSA-2026:41064",
    "RHSA-2026:47388",
    "RHSA-2026:46598",
    "RHSA-2026:67936"
  ],
  "affected_packages": [
    "quay/quay-rhel8:1788593843",
    "satellite/iop-vulnerability-frontend-rhel9:1785937325",
    "rhacm2/console-rhel9:1786908361",
    "quay/quay-rhel8:1784353904",
    "quay/quay-rhel9:1783955846",
    "quay/quay-rhel8:1784351966",
    "openshift4/ose-console-rhel9:1789453727",
    "openshift4/ose-console-rhel9:1788359934",
    "container-native-virtualization/kubevirt-console-plugin-rhel9:1784629964",
    "multicluster-engine/console-mce-rhel9:1786911977",
    "multicluster-engine/console-mce-rhel9:1783348181",
    "multicluster-engine/console-mce-rhel9:1785078604",
    "multicluster-engine/console-mce-rhel9:1786668856",
    "multicluster-engine/console-mce-rhel9:1783351002",
    "quay/quay-rhel8:1783750447",
    "quay/quay-rhel8:1784125838",
    "rhacm2/console-rhel9:1784578812",
    "multicluster-engine/console-mce-rhel9:1784312384",
    "devspaces/dashboard-rhel9:1784737150",
    "openshift4/ose-console-rhel9:1788573287",
    "rhacm2/console-rhel9:1783350952",
    "rhacm2/console-rhel9:1783451729",
    "container-native-virtualization/kubevirt-console-plugin-rhel9:1784844382",
    "satellite/iop-host-inventory-frontend-rhel9:1785922764",
    "satellite/iop-host-inventory-frontend-rhel9:1785956497",
    "rhacm2/console-rhel9:1787335105",
    "rhacm2/console-rhel9:1785078581",
    "openshift4/ose-console-rhel9:1788350963",
    "quay/quay-rhel8:1783751865",
    "openshift4/ose-console-rhel9:1787746382"
  ],
  "bugzilla": "2488565",
  "bugzilla_description": "sanitize-html: `sanitize-html`: Stored Cross-Site Scripting via HTML sanitizer bypass",
  "cvss3_score": "8.1",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-06-12T20:39:47Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-44990.json",
  "severity": "important"
}
severityimportant
A flaw that can easily compromise confidentiality, integrity or availability.
receipt
Source
Red Hat
Its words
important
Read by
field:severity
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-44990",
  "CWE": "CWE-79",
  "advisories": [
    "RHSA-2026:51349",
    "RHSA-2026:36883",
    "RHSA-2026:70267",
    "RHSA-2026:63046",
    "RHSA-2026:57194",
    "RHSA-2026:59593",
    "RHSA-2026:47737",
    "RHSA-2026:42146",
    "RHSA-2026:46903",
    "RHSA-2026:63103",
    "RHSA-2026:41055",
    "RHSA-2026:40262",
    "RHSA-2026:41031",
    "RHSA-2026:46685",
    "RHSA-2026:46885",
    "RHSA-2026:47735",
    "RHSA-2026:57191",
    "RHSA-2026:48124",
    "RHSA-2026:43052",
    "RHSA-2026:51197",
    "RHSA-2026:47451",
    "RHSA-2026:51196",
    "RHSA-2026:66371",
    "RHSA-2026:42796",
    "RHSA-2026:36882",
    "RHSA-2026:60386",
    "RHSA-2026:60441",
    "RHSA-2026:41066",
    "RHSA-2026:41064",
    "RHSA-2026:47388",
    "RHSA-2026:46598",
    "RHSA-2026:67936"
  ],
  "affected_packages": [
    "quay/quay-rhel8:1788593843",
    "satellite/iop-vulnerability-frontend-rhel9:1785937325",
    "rhacm2/console-rhel9:1786908361",
    "quay/quay-rhel8:1784353904",
    "quay/quay-rhel9:1783955846",
    "quay/quay-rhel8:1784351966",
    "openshift4/ose-console-rhel9:1789453727",
    "openshift4/ose-console-rhel9:1788359934",
    "container-native-virtualization/kubevirt-console-plugin-rhel9:1784629964",
    "multicluster-engine/console-mce-rhel9:1786911977",
    "multicluster-engine/console-mce-rhel9:1783348181",
    "multicluster-engine/console-mce-rhel9:1785078604",
    "multicluster-engine/console-mce-rhel9:1786668856",
    "multicluster-engine/console-mce-rhel9:1783351002",
    "quay/quay-rhel8:1783750447",
    "quay/quay-rhel8:1784125838",
    "rhacm2/console-rhel9:1784578812",
    "multicluster-engine/console-mce-rhel9:1784312384",
    "devspaces/dashboard-rhel9:1784737150",
    "openshift4/ose-console-rhel9:1788573287",
    "rhacm2/console-rhel9:1783350952",
    "rhacm2/console-rhel9:1783451729",
    "container-native-virtualization/kubevirt-console-plugin-rhel9:1784844382",
    "satellite/iop-host-inventory-frontend-rhel9:1785922764",
    "satellite/iop-host-inventory-frontend-rhel9:1785956497",
    "rhacm2/console-rhel9:1787335105",
    "rhacm2/console-rhel9:1785078581",
    "openshift4/ose-console-rhel9:1788350963",
    "quay/quay-rhel8:1783751865",
    "openshift4/ose-console-rhel9:1787746382"
  ],
  "bugzilla": "2488565",
  "bugzilla_description": "sanitize-html: `sanitize-html`: Stored Cross-Site Scripting via HTML sanitizer bypass",
  "cvss3_score": "8.1",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-06-12T20:39:47Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-44990.json",
  "severity": "important"
}

Text

sanitize-html: `sanitize-html`: Stored Cross-Site Scripting via HTML sanitizer bypass