{
  "threat_severity" : "Important",
  "public_date" : "2026-06-12T20:39:47Z",
  "bugzilla" : {
    "description" : "sanitize-html: `sanitize-html`: Stored Cross-Site Scripting via HTML sanitizer bypass",
    "id" : "2488565",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2488565"
  },
  "cvss3" : {
    "cvss3_base_score" : "8.1",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-79",
  "details" : [ "ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-controlled content inside a disallowed `xmp` element into live HTML or JavaScript. This is a sanitizer bypass in the default `disallowedTagsMode: 'discard'` path and can lead to stored XSS in applications that render sanitized output back to users. Version 2.17.4 patches the issue.", "A flaw was found in the `sanitize-html` library. Under its default configuration, an attacker can embed malicious content within a disallowed `xmp` element. This vulnerability allows the attacker to bypass the HTML sanitization process, leading to stored Cross-Site Scripting (XSS). Successful exploitation can result in arbitrary code execution or information disclosure when a user views the affected content." ],
  "statement" : "This is an Important flaw. The `sanitize-html` library, used in Red Hat products, is susceptible to a stored Cross-Site Scripting (XSS) bypass. Malicious content within a disallowed `xmp` element can be rendered as live HTML or JavaScript due to a sanitizer bypass in the default configuration. This can lead to arbitrary code execution or information disclosure when affected content is viewed.",
  "affected_release" : [ {
    "product_name" : "multicluster engine for Kubernetes 2.6",
    "release_date" : "2026-07-16T00:00:00Z",
    "advisory" : "RHSA-2026:41055",
    "cpe" : "cpe:/a:redhat:multicluster_engine:2.6::el9",
    "package" : "multicluster-engine/console-mce-rhel9:1783351002"
  }, {
    "product_name" : "multicluster engine for Kubernetes 2.9",
    "release_date" : "2026-07-08T00:00:00Z",
    "advisory" : "RHSA-2026:36883",
    "cpe" : "cpe:/a:redhat:multicluster_engine:2.9::el9",
    "package" : "multicluster-engine/console-mce-rhel9:1783348181"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2.11",
    "release_date" : "2026-07-16T00:00:00Z",
    "advisory" : "RHSA-2026:41064",
    "cpe" : "cpe:/a:redhat:acm:2.11::el9",
    "package" : "rhacm2/console-rhel9:1783350952"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2.14",
    "release_date" : "2026-07-08T00:00:00Z",
    "advisory" : "RHSA-2026:36882",
    "cpe" : "cpe:/a:redhat:acm:2.14::el9",
    "package" : "rhacm2/console-rhel9:1783451729"
  }, {
    "product_name" : "Red Hat Quay 3.1",
    "release_date" : "2026-07-16T00:00:00Z",
    "advisory" : "RHSA-2026:41031",
    "cpe" : "cpe:/a:redhat:quay:3.10::el8",
    "package" : "quay/quay-rhel8:1783750447"
  }, {
    "product_name" : "Red Hat Quay 3.12",
    "release_date" : "2026-07-20T00:00:00Z",
    "advisory" : "RHSA-2026:42146",
    "cpe" : "cpe:/a:redhat:quay:3.12::el8",
    "package" : "quay/quay-rhel8:1783751865"
  }, {
    "product_name" : "Red Hat Quay 3.15",
    "release_date" : "2026-07-21T00:00:00Z",
    "advisory" : "RHSA-2026:42796",
    "cpe" : "cpe:/a:redhat:quay:3.15::el8",
    "package" : "quay/quay-rhel8:1784351966"
  }, {
    "product_name" : "Red Hat Quay 3.16",
    "release_date" : "2026-07-16T00:00:00Z",
    "advisory" : "RHSA-2026:41066",
    "cpe" : "cpe:/a:redhat:quay:3.16::el9",
    "package" : "quay/quay-rhel9:1783955846"
  }, {
    "product_name" : "Red Hat Quay 3.9",
    "release_date" : "2026-07-15T00:00:00Z",
    "advisory" : "RHSA-2026:40262",
    "cpe" : "cpe:/a:redhat:quay:3.9::el8",
    "package" : "quay/quay-rhel8:1784125838"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Hardened Images",
    "fix_state" : "Not affected",
    "package_name" : "opentelemetry-collector",
    "cpe" : "cpe:/a:redhat:hummingbird:1"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "fix_state" : "Affected",
    "package_name" : "opentelemetry-collector-contrib",
    "cpe" : "cpe:/a:redhat:hummingbird:1"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "rhoai/odh-mlflow-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Affected",
    "package_name" : "openshift4/ose-agent-installer-ui-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Affected",
    "package_name" : "openshift4/ose-console",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Affected",
    "package_name" : "openshift4/ose-console-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Dev Spaces",
    "fix_state" : "Affected",
    "package_name" : "devspaces/dashboard-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_devspaces:3"
  }, {
    "product_name" : "Red Hat OpenShift Virtualization 4",
    "fix_state" : "Affected",
    "package_name" : "container-native-virtualization/kubevirt-console-plugin-rhel9",
    "cpe" : "cpe:/a:redhat:container_native_virtualization:4"
  }, {
    "product_name" : "Red Hat Satellite 6",
    "fix_state" : "Affected",
    "package_name" : "nodejs-sanitize-html",
    "cpe" : "cpe:/a:redhat:satellite:6"
  }, {
    "product_name" : "Red Hat Satellite 6",
    "fix_state" : "Affected",
    "package_name" : "satellite/iop-advisor-frontend-rhel9",
    "cpe" : "cpe:/a:redhat:satellite:6"
  }, {
    "product_name" : "Red Hat Satellite 6",
    "fix_state" : "Affected",
    "package_name" : "satellite/iop-host-inventory-frontend-rhel9",
    "cpe" : "cpe:/a:redhat:satellite:6"
  }, {
    "product_name" : "Red Hat Satellite 6",
    "fix_state" : "Affected",
    "package_name" : "satellite/iop-vulnerability-frontend-rhel9",
    "cpe" : "cpe:/a:redhat:satellite:6"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-44990\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-44990\nhttps://github.com/apostrophecms/apostrophe/security/advisories/GHSA-rpr9-rxv7-x643" ],
  "name" : "CVE-2026-44990",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}