Permissive Regular Expression in xmldom - CVE-2026-83609
Published: August 25, 2026 / Updated: September 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to inject markup into serialized XML output.
The vulnerability exists due to permissive regular expression handling in createElementNS, createAttributeNS, createDocumentType, and createAttribute when processing crafted XML names containing an embedded line terminator. A remote attacker can supply a specially crafted qualified name to inject markup into serialized XML output.
When the serialized output is used in an HTML context, this can lead to downstream cross-site scripting. The issue affects the default serialization path, and user interaction is not required.