XML injection in xmldom - CVE-2026-83608
Published: August 25, 2026 / Updated: September 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to inject arbitrary XML markup.
The vulnerability exists due to xml injection in the XML serializer DocumentType.name handling when serializing a document containing an attacker-controlled DocumentType name. A remote attacker can supply a crafted DocumentType name containing a doctype breakout sequence to inject arbitrary XML markup.
If the serialized output is processed as XHTML by a browser-based XML parser, injected script markup may execute. The issue bypasses the requireWellFormed check for DocumentType sibling fields because the name field is emitted verbatim.
Affected software
IBM DataPower Gateway
How to mitigate CVE-2026-83608
IBM DataPower Gateway - addressed in versions 10.5.0.23, 10.6.0.11, 11.0.0.3