CVE-2026-44990
Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.
NVD · uneditedApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-controlled content inside a disallowed `xmp` element into live HTML or JavaScript. This is a sanitizer bypass in the default `disallowedTagsMode: 'discard'` path and can lead to stored XSS in applications that render sanitized output back to users. Version 2.17.4 patches the issue.
Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.
dbcve analysis · high confidenceThe sanitize-html library versions prior to 2.17.4 contain a sanitizer bypass where attacker-controlled content inside a disallowed `xmp` element can be transformed into live HTML or JavaScript in the default `disallowedTagsMode: 'discard'` configuration, enabling stored XSS in applications that render sanitized content.
Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.
CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.
From the vector- Attack vector
- Network
- Complexity
- Low
- Privileges
- None
- User interaction
- Required
- Scope
- Changed
- Confidentiality
- High
- Integrity
- High
- Availability
- None
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.
dbcve checksWork through these to decide whether this CVE applies to you.
-
Check sanitize-html versionRun `npm list sanitize-html` or inspect the version field in node_modules/sanitize-html/package.jsonAffected if The installed version is earlier than 2.17.4 (e.g., 2.17.3, 2.16.0, etc.)
-
Identify sanitize-html usage in your codebaseSearch for `require('sanitize-html')` or `import ... from 'sanitize-html'` to locate where sanitization is performedAffected if Your application uses sanitize-html to clean user-supplied HTML content
-
Verify sanitize-html configurationInspect the options object passed to sanitize-html() and look for the disallowedTagsMode settingAffected if disallowedTagsMode is set to 'discard' (the default) or is not explicitly set to 'escape' or 'recursiveEscape'
-
Check if xmp tags can appear in user contentReview your data flow to determine whether users can submit content containing <xmp> tags that gets processed by sanitize-htmlAffected if User-provided HTML containing <xmp> elements passes through the sanitizer before rendering
You are affected if sanitize-html version is below 2.17.4 AND your application sanitizes user content using the default configuration, and <xmp> tags from users can reach the sanitizer.
Generated from the published advisory. Verify against your own configuration.
Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.
dbcve · scopedUpgrade sanitize-html to version 2.17.4 or later to patch the XSS bypass in the `xmp` element handling.
sanitize-html version 2.17.4
- Update the sanitize-html package to version 2.17.4 or later using your package manager (e.g., npm install [email protected] or npm update sanitize-html)
- Verify that the xmp element is now properly handled in the disallowed tags path
- Test that sanitized HTML output no longer executes malicious scripts injected within xmp tags
- Redeploy the updated application to production environments
Generated from the published advisory — verify against the referenced sources before acting.
- Consultation2.0 h
- Implementation2.0 h
- Testing3.0 h
- Review / QA1.0 h
An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $2,224.
Scan for this in your stack
Free · runs locallyCheck whether your project pulls in CVE-2026-44990 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.
References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.
Primary sources- github.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- bugzilla.redhat.com
- security.access.redhat.com
- nvd.nist.gov
Practitioner notes
ContributedPeer-ranked notes from engineers who’ve handled CVE-2026-44990 in production — separate from our analysis above.
The advisory tells you what broke. It rarely tells you what actually worked. If you’ve dealt with this one, that detail is what the next engineer is searching for.
- The version that genuinely resolved it — not the one the vendor claimed
- A config change or rule that shut the vector down
- A gotcha in the upgrade path that cost you an afternoon
No notes yet
Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.
A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.
- Verified mitigations, workarounds, and config changes
- Version or environment caveats, and links to real fixes
- No weaponised exploit code, or anything meant to cause harm
- No spam, self-promotion, credentials, or personal data