Permissive Regular Expression in xmldom - CVE-2026-83617
Published: August 25, 2026 / Updated: September 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to inject XML or markup structure.
The vulnerability exists due to permissive regular expression in the requireWellFormed serializer element and attribute name validation when serializing a node with attacker-influenced element or attribute names containing an embedded line terminator. A remote attacker can supply a crafted name that passes validation and is serialized verbatim to inject XML or markup structure.
Downstream cross-site scripting is possible if the serialized output is placed into an HTML context. The issue is reachable when names are set through programmatic DOM construction and serialization is performed with requireWellFormed enabled.