XML injection in xmldom - CVE-2026-83608

 

XML injection in xmldom - CVE-2026-83608

Published: August 25, 2026 / Updated: September 2, 2026


Vulnerability identifier: #VU145132
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-83608
CWE-ID: CWE-91
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to inject arbitrary XML markup.

The vulnerability exists due to xml injection in the XML serializer DocumentType.name handling when serializing a document containing an attacker-controlled DocumentType name. A remote attacker can supply a crafted DocumentType name containing a doctype breakout sequence to inject arbitrary XML markup.

If the serialized output is processed as XHTML by a browser-based XML parser, injected script markup may execute. The issue bypasses the requireWellFormed check for DocumentType sibling fields because the name field is emitted verbatim.


Affected software

xmldom
IBM DataPower Gateway

How to mitigate CVE-2026-83608

Install security update from vendor's website.

xmldom - addressed in versions 0.8.15, 0.9.12
IBM DataPower Gateway - addressed in versions 10.5.0.23, 10.6.0.11, 11.0.0.3

External References

Related Security Bulletins