SB2026082538 - Multiple vulnerabilities in xmldom
Published: August 25, 2026 Updated: September 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 12 vulnerabilities.
1) Permissive Regular Expression (CVE-ID: CVE-2026-83617)
CWE-ID: CWE-625 - Permissive Regular Expression
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to inject XML or markup structure.
The vulnerability exists due to permissive regular expression in the requireWellFormed serializer element and attribute name validation when serializing a node with attacker-influenced element or attribute names containing an embedded line terminator. A remote attacker can supply a crafted name that passes validation and is serialized verbatim to inject XML or markup structure.
Downstream cross-site scripting is possible if the serialized output is placed into an HTML context. The issue is reachable when names are set through programmatic DOM construction and serialization is performed with requireWellFormed enabled.
2) Permissive Regular Expression (CVE-ID: CVE-2026-83618)
CWE-ID: CWE-625 - Permissive Regular Expression
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to inject XML markup into the DOCTYPE declaration.
The vulnerability exists due to permissive regular expression validation in the requireWellFormed DocumentType publicId/systemId serializer check when processing a DocumentType with an embedded line terminator in publicId or systemId. A remote attacker can supply a crafted publicId or systemId value to inject XML markup into the DOCTYPE declaration.
Only the opt-in serialization path with requireWellFormed: true is affected.
3) Improper Validation of Syntactic Correctness of Input (CVE-ID: CVE-2026-83611)
CWE-ID: CWE-1286 - Improper Validation of Syntactic Correctness of Input
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a well-formedness validation check.
The vulnerability exists due to improper validation of syntactic correctness of input in the xmldom parser when parsing XML end tags whose valid name is followed by a line break and trailing content. A remote attacker can supply specially crafted XML input to bypass a well-formedness validation check.
The trailing content is silently discarded, and the resulting DOM can appear as a normal single-root document instead of producing a parse error.
4) Permissive Regular Expression (CVE-ID: CVE-2026-83609)
CWE-ID: CWE-625 - Permissive Regular Expression
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to inject markup into serialized XML output.
The vulnerability exists due to permissive regular expression handling in createElementNS, createAttributeNS, createDocumentType, and createAttribute when processing crafted XML names containing an embedded line terminator. A remote attacker can supply a specially crafted qualified name to inject markup into serialized XML output.
When the serialized output is used in an HTML context, this can lead to downstream cross-site scripting. The issue affects the default serialization path, and user interaction is not required.
5) XML injection (CVE-ID: CVE-2026-83608)
CWE-ID: CWE-91 - XML Injection
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to inject arbitrary XML markup.
The vulnerability exists due to xml injection in the XML serializer DocumentType.name handling when serializing a document containing an attacker-controlled DocumentType name. A remote attacker can supply a crafted DocumentType name containing a doctype breakout sequence to inject arbitrary XML markup.
If the serialized output is processed as XHTML by a browser-based XML parser, injected script markup may execute. The issue bypasses the requireWellFormed check for DocumentType sibling fields because the name field is emitted verbatim.
6) Inefficient Algorithmic Complexity (CVE-ID: CVE-2026-83614)
CWE-ID: CWE-407 - Inefficient Algorithmic Complexity
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity in the DOMParser.parseFromString parsing path and normalize() when processing crafted malformed XML input or adjacent text nodes. A remote attacker can send a specially crafted XML document to cause a denial of service.
The parser path is reachable under default options from network-delivered XML, and the same quadratic behavior is also reachable through an explicit normalize() call on a programmatically built DOM containing adjacent text nodes.
7) Inefficient Algorithmic Complexity (CVE-ID: CVE-2026-83613)
CWE-ID: CWE-407 - Inefficient Algorithmic Complexity
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity in attribute deduplication in NamedNodeMap during XML parsing when processing a well-formed XML document containing a single element with many distinct attributes. A remote attacker can submit a specially crafted XML document to cause a denial of service.
The issue is triggered by valid input and does not require malformed markup, error recovery, namespace declarations, nesting, or non-default parser options.
8) Inefficient regular expression complexity (CVE-ID: CVE-2026-83619)
CWE-ID: CWE-1333 - Inefficient Regular Expression Complexity
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient regular expression complexity in the end-tag parser in lib/sax.js when parsing an XML end tag whose name is followed by a long run of whitespace and then a non-whitespace character via DOMParser.parseFromString. A remote attacker can send a specially crafted XML document to cause a denial of service.
The issue is reachable under default options before any validity check and can stall the Node.js event loop during a single parse.
9) Improper Encoding or Escaping of Output (CVE-ID: CVE-2026-83610)
CWE-ID: CWE-116 - Improper Encoding or Escaping of Output
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to inject XML markup into serialized output.
The vulnerability exists due to improper encoding or escaping of output in the XML serializer ENTITY_REFERENCE_NODE serialization path when serializing an EntityReference node with requireWellFormed enabled. A remote attacker can supply an invalid EntityReference name to inject XML markup into serialized output.
The main affected scenario is applications that directly create an EntityReference from attacker-controlled input and later reparse the serialized fragment in an XML context.
10) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-83615)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the XML parser namespace handling logic when parsing crafted XML documents with deeply nested elements that each declare a unique namespace prefix. A remote attacker can send a specially crafted XML document to cause a denial of service.
A small, highly compressible network-delivered payload can trigger quadratic peak memory consumption during parsing and crash the process before application-level validation runs.
11) XML injection (CVE-ID: CVE-2026-83616)
CWE-ID: CWE-91 - XML Injection
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to inject arbitrary XML content into serialized output.
The vulnerability exists due to xml injection in Document.createProcessingInstruction() and the XML serializer when processing user-controlled processing-instruction target values during serialization. A remote attacker can supply a specially crafted target string to inject arbitrary XML content into serialized output.
If the serialized output is later processed as XHTML by a browser, injected script elements may execute. Exploitation requires application code to create processing instructions from untrusted target input and serialize the resulting document.
12) Improper Handling of Case Sensitivity (CVE-ID: CVE-2026-83612)
CWE-ID: CWE-178 - Improper Handling of Case Sensitivity
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of case sensitivity in the HTML raw-text parser when parsing untrusted HTML in HTML mode with mixed-case closing tags for raw-text elements. A remote attacker can send a specially crafted HTML document to cause a denial of service.
Only HTML mode is affected, and exploitation requires the application to parse and serialize untrusted text/html containing mixed-case closing tags for script, style, textarea, or title elements.
Remediation
Install update from vendor's website.
References
- https://github.com/xmldom/xmldom/security/advisories/GHSA-jxjr-3g7g-3944
- https://github.com/xmldom/xmldom/security/advisories/GHSA-vr34-hp96-76pp
- https://github.com/xmldom/xmldom/security/advisories/GHSA-6h8r-xr42-gp59
- https://github.com/xmldom/xmldom/security/advisories/GHSA-3px3-54cx-rmw9
- https://github.com/xmldom/xmldom/security/advisories/GHSA-27p8-2357-5qqv
- https://github.com/xmldom/xmldom/blob/bb7a085dc5ba1eea3212388509b97bb4b4af32b9/lib/dom.js#L3256-L3283
- https://github.com/xmldom/xmldom/security/advisories/GHSA-93r5-fhx6-vmg9
- https://github.com/xmldom/xmldom/security/advisories/GHSA-8344-3jmq-59r6
- https://github.com/xmldom/xmldom/security/advisories/GHSA-x4fp-j954-r2f4
- https://github.com/xmldom/xmldom/blob/e5c14802592685bb872c042c54c3f73758875c85/lib/sax.js#L120
- https://github.com/xmldom/xmldom/security/advisories/GHSA-6gmq-8vp8-gcm6
- https://github.com/xmldom/xmldom/security/advisories/GHSA-965w-775f-mr7g
- https://github.com/xmldom/xmldom/blob/08a22d78e4bc50f12ce9f5090b8d96ee6031ac7b/lib/sax.js#L467-L540
- https://github.com/xmldom/xmldom/security/advisories/GHSA-c7q8-3ch8-vqpv
- https://github.com/xmldom/xmldom/security/advisories/GHSA-6mj3-qw4j-hgrw