Permissive Regular Expression in xmldom - CVE-2026-83617

 

Permissive Regular Expression in xmldom - CVE-2026-83617

Published: August 25, 2026 / Updated: September 2, 2026


Vulnerability identifier: #VU145128
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-83617
CWE-ID: CWE-625
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to inject XML or markup structure.

The vulnerability exists due to permissive regular expression in the requireWellFormed serializer element and attribute name validation when serializing a node with attacker-influenced element or attribute names containing an embedded line terminator. A remote attacker can supply a crafted name that passes validation and is serialized verbatim to inject XML or markup structure.

Downstream cross-site scripting is possible if the serialized output is placed into an HTML context. The issue is reachable when names are set through programmatic DOM construction and serialization is performed with requireWellFormed enabled.


Affected software

xmldom

How to mitigate CVE-2026-83617

Install security update from vendor's website.

xmldom - update to 0.9.12

External References

Related Security Bulletins