Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-48910

29
FAUCET Score

CVE-2024-48910 describes a critical prototype pollution vulnerability in DOMPurify, a widely used XSS sanitizer for HTML, MathML, and SVG, affecting versions prior to 2.4.2. This flaw carries a CVSS score of 9.8 (Critical), indicating it can be exploited remotely with low attack complexity, potentially leading to complete compromise of confidentiality, integrity, and availability. While no active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion has been observed, the high FAUCET Risk Score of 81/100 underscores its severity.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.4.2CPE matchmatch criteria
cpe:2.3:a:cure53:dompurify:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.1CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.18%
Probability of exploitation in next 30 days
EPSS Percentile
64.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0118 is in the 50th percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (31)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: dompurifyFixed in: 2.4.2
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.5Fixed in: advanced-cluster-security/rhacs-main-rhel8:4.5.5-3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.14Fixed in: openshift4/ose-monitoring-plugin-rhel8:v4.14.0-202411130434.p0.gb57ebe7.assembly.stream.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.17Fixed in: openshift4/ose-networking-console-plugin-rhel9:v4.17.0-202501150934.p0.g0244dff.assembly.stream.el9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.17Fixed in: openshift4/nmstate-console-plugin-rhel9:v4.17.0-202501301204.p0.gcffdc60.assembly.stream.el9
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.14-RHEL-9Fixed in: odf4/ocs-client-console-rhel9:v4.14.18-2
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.14-RHEL-9Fixed in: odf4/odf-console-rhel9:v4.14.18-3
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.14-RHEL-9Fixed in: odf4/odf-multicluster-console-rhel9:v4.14.18-2
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.15-RHEL-9Fixed in: odf4/ocs-client-console-rhel9:v4.15.14-2
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.15-RHEL-9Fixed in: odf4/odf-console-rhel9:v4.15.14-2
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.15-RHEL-9Fixed in: odf4/odf-multicluster-console-rhel9:v4.15.14-2
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.16-RHEL-9Fixed in: odf4/ocs-client-console-rhel9:v4.16.5-2
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.16-RHEL-9Fixed in: odf4/odf-console-rhel9:v4.16.5-2
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.17-RHEL-9Fixed in: odf4/ocs-client-console-rhel9:v4.17.2-1
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.17-RHEL-9Fixed in: odf4/odf-console-rhel9:v4.17.2-1
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.17-RHEL-9Fixed in: odf4/odf-multicluster-console-rhel9:v4.17.2-1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.12Fixed in: openshift4/ose-console:sha256:2281a7cabe90a7f399d8c891b7df539ff66cc521f859cc0d0d8a9f12c5e6511e
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.13Fixed in: openshift4/ose-console:sha256:205f1a4ac1a6d1ca7fc14a5b400edefbf0e04a2a475b106c53e28cceebdf70ce
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.14Fixed in: openshift4/ose-console:sha256:5593067bbf79e50ab9ed89c684c8ee03b4b2a0b6443068459967df623c0643de
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.15Fixed in: openshift4/ose-console:sha256:71b555c5e31fb0c3ad0c512f937027a14b1dfcdd4598438bda3252a8a2100c1c
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.16Fixed in: openshift4/ose-console-rhel9:sha256:38b21746bf09e4c0bf7f4021ed2ee26130cae53d0e90d0019991aad23f4a13b0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.17Fixed in: openshift4/ose-console-rhel9:sha256:bff805794d6bd6ab6312648f8df3b5c117a4f4337b423b934266f0222f84ad38
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.18Fixed in: openshift4/ose-console-rhel9:sha256:9c85135cff5d01eee0e07456cb207e14beb0a7642d9768853ae086eb827929d8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.19Fixed in: openshift4/ose-console-rhel9:sha256:b9a09e5806f5a9ace5cfd36f15a3362117eb47a9528607a1d7e25fe647ad4bac
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.2Fixed in: openshift4/ose-console-rhel9:sha256:63c0adf8e72dada3c11ae906ffaa2b3fda5dc10d0ad16c62956f19e1a307ff59
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.16-RHEL-9Fixed in: odf4/odf-multicluster-console-rhel9:v4.16.5-2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.4Fixed in: advanced-cluster-security/rhacs-main-rhel8:4.4.6-2
View patch
redhatno patchvia redhat_api
Product: Red Hat OpenShift Virtualization 4Fixed in: container-native-virtualization/kubevirt-console-plugin
redhatno patchvia redhat_api
Product: Red Hat OpenShift Virtualization 4Fixed in: container-native-virtualization/kubevirt-console-plugin-rhel9
redhatend of lifevia redhat_api
Product: Node HealthCheck OperatorFixed in: workload-availability/node-remediation-console-rhel8

Vendor Advisories (2)

npmGHSA-p3vf-v8qc-cwcrcritical

DOMPurify vulnerable to tampering by prototype polution

Oct 31, 2024
redhatCVE-2024-48910Important

dompurify: DOMPurify vulnerable to tampering by prototype pollution

Oct 31, 2024

References

lists.debian.org / debian-lts-announce/2025/02/msg00010.html
github.com / cure53/DOMPurify/commit/d1dd0374caef2b4c56c3bd09fe1988c3479166dc
Patch
github.com / cure53/DOMPurify/security/advisories/GHSA-p3vf-v8qc-cwcr
Vendor Advisory