XML injection in xmldom - CVE-2026-83607
Published: August 14, 2026 / Updated: September 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to inject arbitrary content into serialized XML or HTML output.
The vulnerability exists due to xml injection in Document.createElement() and XMLSerializer.serializeToString() when processing a user-controlled element name during serialization. A remote attacker can supply a specially crafted tagName value to inject arbitrary content into serialized XML or HTML output.
The issue bypasses the serializer's requireWellFormed check and can lead to cross-site scripting when the serialized output is consumed by a browser.
Affected software
IBM DataPower Gateway
How to mitigate CVE-2026-83607
IBM DataPower Gateway - addressed in versions 10.5.0.23, 10.6.0.11, 11.0.0.3