CVE-2026-44990
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of sanitize-html prior to 2.17.4 can turn attacker-controlled content inside a disallowed xmp element into live HTML or JavaScript. This is a sanitizer bypass in the default disallowedTagsMode: 'discard' path and can lead to stored XSS in applications that render sanitized output back to users. Version 2.17.4 patches the issue.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44990.json, https://access.redhat.com/errata/RHSA-2026:36882, https://access.redhat.com/errata/RHSA-2026:36883, https://access.redhat.com/errata/RHSA-2026:40262, https://access.redhat.com/errata/RHSA-2026:41031, https://access.redhat.com/errata/RHSA-2026:41055, https://access.redhat.com/errata/RHSA-2026:41064, https://access.redhat.com/errata/RHSA-2026:41066, https://access.redhat.com/errata/RHSA-2026:42146, https://access.redhat.com/errata/RHSA-2026:42796, https://access.redhat.com/errata/RHSA-2026:43052, https://access.redhat.com/errata/RHSA-2026:46598, https://access.redhat.com/errata/RHSA-2026:46685, https://access.redhat.com/errata/RHSA-2026:46885, https://access.redhat.com/errata/RHSA-2026:46903, https://access.redhat.com/errata/RHSA-2026:47735, https://access.redhat.com/errata/RHSA-2026:47737, https://access.redhat.com/errata/RHSA-2026:48124, https://access.redhat.com/errata/RHSA-2026:51196, https://access.redhat.com/errata/RHSA-2026:51197, https://access.redhat.com/errata/RHSA-2026:51349, https://access.redhat.com/security/cve/CVE-2026-44990, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44990.json, https://github.com/apostrophecms/apostrophe/security/advisories/GHSA-rpr9-rxv7-x643, https://nvd.nist.gov/vuln/detail/CVE-2026-44990, https://bugzilla.redhat.com/show_bug.cgi?id=2488565