
My first CVE ever is a bypass for non other than DOMPurify. GitHub is taking their sweet time populating the CVE Record though. Writeup coming soon. https://github.com/cure53/DOMPurify/security/advisories/GHSA-87xg-pxx2-7hvx CVE-2026-47423
Post summary
The tweet announces a new CVE involving a DOMPurify bypass and links to a GitHub advisory where a PoC is likely provided, but no exploit code, active exploitation, patch, or technical details are disclosed.

