{
  "document": {
    "aggregate_severity": {
      "namespace": "https://www.suse.com/support/security/rating/",
      "text": "moderate"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright 2024 SUSE LLC. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "summary",
        "text": "SUSE CVE-2026-49978",
        "title": "Title"
      },
      {
        "category": "description",
        "text": "DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE sanitization could skip shadow contents attached to an element inside <template>.content, allowing attacker-controlled markup such as event handlers, JavaScript URLs, or scripts to survive and execute when an application cloned and inserted the sanitized template. This issue is fixed in version 3.4.7.",
        "title": "Description of the CVE"
      },
      {
        "category": "legal_disclaimer",
        "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).",
        "title": "Terms of use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://www.suse.com/support/security/contact/",
      "name": "SUSE Product Security Team",
      "namespace": "https://www.suse.com/"
    },
    "references": [
      {
        "category": "external",
        "summary": "CVE-2026-49978",
        "url": "https://www.suse.com/security/cve/CVE-2026-49978"
      },
      {
        "category": "external",
        "summary": "SUSE Security Ratings",
        "url": "https://www.suse.com/support/security/rating/"
      },
      {
        "category": "external",
        "summary": "SUSE Bug 1271510 for CVE-2026-49978",
        "url": "https://bugzilla.suse.com/1271510"
      }
    ],
    "title": "SUSE CVE CVE-2026-49978",
    "tracking": {
      "current_release_date": "2026-09-15T02:03:47Z",
      "generator": {
        "date": "2026-07-16T17:58:20Z",
        "engine": {
          "name": "cve-database.git:bin/generate-csaf-vex.pl",
          "version": "1"
        }
      },
      "id": "CVE-2026-49978",
      "initial_release_date": "2026-07-16T17:58:20Z",
      "revision_history": [
        {
          "date": "2026-07-16T17:58:20Z",
          "number": "2",
          "summary": "vulnerabilities added,references added,severity changed from  to moderate"
        },
        {
          "date": "2026-09-10T17:01:42Z",
          "number": "3",
          "summary": "unknown changes"
        },
        {
          "date": "2026-09-15T02:03:47Z",
          "number": "4",
          "summary": "more updates marked as affected"
        }
      ],
      "status": "interim",
      "version": "4"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise Module for SAP Applications 15 SP4",
                "product": {
                  "name": "SUSE Linux Enterprise Module for SAP Applications 15 SP4",
                  "product_id": "SUSE Linux Enterprise Module for SAP Applications 15 SP4",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sle-module-sap-applications:15:sp4"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise Module for SAP Applications 15 SP5",
                "product": {
                  "name": "SUSE Linux Enterprise Module for SAP Applications 15 SP5",
                  "product_id": "SUSE Linux Enterprise Module for SAP Applications 15 SP5",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sle-module-sap-applications:15:sp5"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise Module for SAP Applications 15 SP7",
                "product": {
                  "name": "SUSE Linux Enterprise Module for SAP Applications 15 SP7",
                  "product_id": "SUSE Linux Enterprise Module for SAP Applications 15 SP7",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sle-module-sap-applications:15:sp7"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise Server 16.1",
                "product": {
                  "name": "SUSE Linux Enterprise Server 16.1",
                  "product_id": "SUSE Linux Enterprise Server 16.1",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sles:16:16.1:server"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise Server for SAP Applications 15 SP4",
                "product": {
                  "name": "SUSE Linux Enterprise Server for SAP Applications 15 SP4",
                  "product_id": "SUSE Linux Enterprise Server for SAP Applications 15 SP4",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sles_sap:15:sp4"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise Server for SAP Applications 15 SP5",
                "product": {
                  "name": "SUSE Linux Enterprise Server for SAP Applications 15 SP5",
                  "product_id": "SUSE Linux Enterprise Server for SAP Applications 15 SP5",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sles_sap:15:sp5"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise Server for SAP Applications 15 SP7",
                "product": {
                  "name": "SUSE Linux Enterprise Server for SAP Applications 15 SP7",
                  "product_id": "SUSE Linux Enterprise Server for SAP Applications 15 SP7",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sles_sap:15:sp7"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise Server for SAP applications 16.1",
                "product": {
                  "name": "SUSE Linux Enterprise Server for SAP applications 16.1",
                  "product_id": "SUSE Linux Enterprise Server for SAP applications 16.1",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sles:16:16.1:server-sap"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "trento-web",
                "product": {
                  "name": "trento-web",
                  "product_id": "trento-web",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/suse/trento-web@?upstream=trento-web.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "velociraptor",
                "product": {
                  "name": "velociraptor",
                  "product_id": "velociraptor",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:rapid7:velociraptor:*:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/velociraptor@?upstream=velociraptor.src.rpm"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "SUSE Linux Enterprise"
          }
        ],
        "category": "vendor",
        "name": "SUSE"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "trento-web as component of SUSE Linux Enterprise Server for SAP Applications 15 SP4",
          "product_id": "SUSE Linux Enterprise Server for SAP Applications 15 SP4:trento-web"
        },
        "product_reference": "trento-web",
        "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 15 SP4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "trento-web as component of SUSE Linux Enterprise Module for SAP Applications 15 SP4",
          "product_id": "SUSE Linux Enterprise Module for SAP Applications 15 SP4:trento-web"
        },
        "product_reference": "trento-web",
        "relates_to_product_reference": "SUSE Linux Enterprise Module for SAP Applications 15 SP4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "trento-web as component of SUSE Linux Enterprise Server for SAP Applications 15 SP5",
          "product_id": "SUSE Linux Enterprise Server for SAP Applications 15 SP5:trento-web"
        },
        "product_reference": "trento-web",
        "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 15 SP5"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "trento-web as component of SUSE Linux Enterprise Module for SAP Applications 15 SP5",
          "product_id": "SUSE Linux Enterprise Module for SAP Applications 15 SP5:trento-web"
        },
        "product_reference": "trento-web",
        "relates_to_product_reference": "SUSE Linux Enterprise Module for SAP Applications 15 SP5"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "trento-web as component of SUSE Linux Enterprise Server for SAP Applications 15 SP7",
          "product_id": "SUSE Linux Enterprise Server for SAP Applications 15 SP7:trento-web"
        },
        "product_reference": "trento-web",
        "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 15 SP7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "trento-web as component of SUSE Linux Enterprise Module for SAP Applications 15 SP7",
          "product_id": "SUSE Linux Enterprise Module for SAP Applications 15 SP7:trento-web"
        },
        "product_reference": "trento-web",
        "relates_to_product_reference": "SUSE Linux Enterprise Module for SAP Applications 15 SP7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "velociraptor as component of SUSE Linux Enterprise Server 16.1",
          "product_id": "SUSE Linux Enterprise Server 16.1:velociraptor"
        },
        "product_reference": "velociraptor",
        "relates_to_product_reference": "SUSE Linux Enterprise Server 16.1"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "trento-web as component of SUSE Linux Enterprise Server for SAP applications 16.1",
          "product_id": "SUSE Linux Enterprise Server for SAP applications 16.1:trento-web"
        },
        "product_reference": "trento-web",
        "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP applications 16.1"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "velociraptor as component of SUSE Linux Enterprise Server for SAP applications 16.1",
          "product_id": "SUSE Linux Enterprise Server for SAP applications 16.1:velociraptor"
        },
        "product_reference": "velociraptor",
        "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP applications 16.1"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-49978",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-49978"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE sanitization could skip shadow contents attached to an element inside <template>.content, allowing attacker-controlled markup such as event handlers, JavaScript URLs, or scripts to survive and execute when an application cloned and inserted the sanitized template. This issue is fixed in version 3.4.7.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "known_affected": [
          "SUSE Linux Enterprise Module for SAP Applications 15 SP4:trento-web",
          "SUSE Linux Enterprise Module for SAP Applications 15 SP5:trento-web",
          "SUSE Linux Enterprise Module for SAP Applications 15 SP7:trento-web",
          "SUSE Linux Enterprise Server 16.1:velociraptor",
          "SUSE Linux Enterprise Server for SAP Applications 15 SP4:trento-web",
          "SUSE Linux Enterprise Server for SAP Applications 15 SP5:trento-web",
          "SUSE Linux Enterprise Server for SAP Applications 15 SP7:trento-web",
          "SUSE Linux Enterprise Server for SAP applications 16.1:trento-web",
          "SUSE Linux Enterprise Server for SAP applications 16.1:velociraptor"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-49978",
          "url": "https://www.suse.com/security/cve/CVE-2026-49978"
        },
        {
          "category": "external",
          "summary": "SUSE Security Ratings",
          "url": "https://www.suse.com/support/security/rating/"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1271510 for CVE-2026-49978",
          "url": "https://bugzilla.suse.com/1271510"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-06-15T22:24:26Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-49978"
    }
  ]
}