Permissive Regular Expression in xmldom - CVE-2026-83618
Published: August 25, 2026 / Updated: September 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to inject XML markup into the DOCTYPE declaration.
The vulnerability exists due to permissive regular expression validation in the requireWellFormed DocumentType publicId/systemId serializer check when processing a DocumentType with an embedded line terminator in publicId or systemId. A remote attacker can supply a crafted publicId or systemId value to inject XML markup into the DOCTYPE declaration.
Only the opt-in serialization path with requireWellFormed: true is affected.