DOMPurify 3.3.0 will soon be released, with this likely being the most important change in a long time:
https://github.com/cure53/DOMPurify/pull/1150
@cure53.infosec.exchange.ap.brid.gy
And there is fire where we walk. [bridged from https://infosec.exchange/@cure53 on the fediverse by https://fed.brid.gy/ ]
DOMPurify 3.3.0 will soon be released, with this likely being the most important change in a long time:
https://github.com/cure53/DOMPurify/pull/1150
How do you like our new website we learned about just today?
https://dompurify.com/
Please make sure to run dompurify.exe on Windows 11 for best possible experience and Full HD.
DOMPurify 3.2.7 has been released today, adding several fixes and improvements.
https://github.com/cure53/DOMPurify/releases/tag/3.2.7
Thanks to all folks who contributed π
A stuffed doll of Jean-Luc Picard, captain of the starship Enterprise in the television program Star Trek: The Next Generation, sits on a shelf in a used goods store right next to a packaged of LED lights. The picture on the front of the box show four lights while the written advertising on the box says there are FIVE lights in the package.
Somebody on the internet is very good at subtle humor.
#StarTrekTNG
#Humor
In the last five years, we've gone from "employees will never have to go into an office" to "employees need to be in the office because creative and innovative work can only be done face-to-face between humans" to "lol we don't need humans"
26.06.2025 16:14 β π 40 π 289 π¬ 5 π 0libxslt project maintainer steps down, citing the amount of time it takes to triage embargoed security issues.
βIβve been doing this long enough to know that most of the secrecy around security issues is just theater. All the βbest practicesβ like OpenSSF Scorecards are just an attempt by big [β¦]
From a pure penetration testing perspective, ZUGFeRD has been such a gift in 2025... thank you so much, German government π
19.06.2025 11:50 β π 0 π 0 π¬ 0 π 0@publicvoit If we did that for DOMPurify and HTML, we'd be doing nothing else but populate that list all day long π
03.06.2025 13:34 β π 0 π 0 π¬ 0 π 0Remember this tiny change to the HTML spec?
It just prevented a critical bug in an application we are currently testing.
https://github.com/whatwg/html/commit/e21bd3b4a94bfdbc23d863128e0b207be9821a0f
β€οΈ cc @freddy @securitymb
Small change to HTML with massive impact on eliminating mXSS attacks
https://github.com/whatwg/html/commit/e21bd3b4a94bfdbc23d863128e0b207be9821a0f
DOMPurify 3.2.6 has been release with several smaller fixes and improvements, thanks to all who contributed π
https://github.com/cure53/DOMPurify/releases/tag/3.2.6
Hopefully this will also help with the CI/CD issues that arose after the fake CVE was posted last week.
Detecting malicious Unicode in #curl
https://daniel.haxx.se/blog/2025/05/16/detecting-malicious-unicode/
The advisory has been revoked, thanks folks over at Snyk for being super fast and responsive π β€οΈ
16.05.2025 14:44 β π 0 π 0 π¬ 0 π 0@bagder No worries and thanks nevertheless π
16.05.2025 14:11 β π 0 π 0 π¬ 0 π 0@bagder That is true indeed.
Also, sorry for summoning you, we hoped you might per change know of a quick path to escalate this to Snyk so we can have that CVE be reviewed.
Right now trying learn how, as this is a first for us.
cc @bagder who likely already has experience with this kind of bug report π
16.05.2025 13:32 β π 0 π 0 π¬ 1 π 0Sadly, someone dropped a nonsense CVE on DOMPurify and now people are panicking and send us emails asking when the "fix" will be released.
https://security.snyk.io/vuln/SNYK-JS-DOMPURIFY-10176060
Does anyone here has a personal contact at Snyk who might be able to help with getting rid of this?
Two penguins, one is well visible, the other one... almost visible too!
Scientists recently visualized it, can you finally see how insecure Linux really is?
Just use Windows and set AI=On and all this will go away #securitytips #youarewelcome
DOMPurify 3.2.5 has been released, adding several fixes and improvements.
https://github.com/cure53/DOMPurify/releases/tag/3.2.5
Thanks to all folks who contributed π
DOMPurify 3.2.4 has been released, adding some smaller fixes and convenience features...
And, also fixing a conditional, config-depended and very smart bypass - related to the SAFE_FOR_TEMPLATES mode, thanks @nsysean π
https://github.com/cure53/DOMPurify/releases/tag/3.2.4
If you don't use [β¦]