XML injection in xmldom - CVE-2026-83605

 

XML injection in xmldom - CVE-2026-83605

Published: August 14, 2026 / Updated: September 2, 2026


Vulnerability identifier: #VU142548
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-83605
CWE-ID: CWE-91
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to inject attributes into serialized output.

The vulnerability exists due to improper input validation in Element.setAttribute() and XMLSerializer when processing user-controlled attribute names during serialization. A remote attacker can supply a crafted attribute name to inject attributes into serialized output.

This can include injection of event handler attributes into HTML output consumed by browsers, and the issue occurs because attribute names are emitted verbatim while only attribute values are escaped.


Affected software

xmldom
IBM DataPower Gateway

How to mitigate CVE-2026-83605

Install security update from vendor's website.

xmldom - addressed in versions 0.8.14, 0.9.11
IBM DataPower Gateway - addressed in versions 10.5.0.23, 10.6.0.11, 11.0.0.3

External References

Related Security Bulletins