
CVE-2026-40301 DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.10, DOMSanitizer::sanitize() allows <style> elements in SVG content but never inspects t… https://www.cve.org/CVERecord?id=CVE-2026-40301
Post summary
CVE-2026-40301 exposes a DOM sanitization flaw that allows <style> tags in SVG content before patch version 1.0.10 of DOMSanitizer for PHP 7.3+, with the fix available in the mentioned version.

