Improper Encoding or Escaping of Output in xmldom - CVE-2026-83610

 

Improper Encoding or Escaping of Output in xmldom - CVE-2026-83610

Published: August 25, 2026 / Updated: September 2, 2026


Vulnerability identifier: #VU145136
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-83610
CWE-ID: CWE-116
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to inject XML markup into serialized output.

The vulnerability exists due to improper encoding or escaping of output in the XML serializer ENTITY_REFERENCE_NODE serialization path when serializing an EntityReference node with requireWellFormed enabled. A remote attacker can supply an invalid EntityReference name to inject XML markup into serialized output.

The main affected scenario is applications that directly create an EntityReference from attacker-controlled input and later reparse the serialized fragment in an XML context.


Affected software

xmldom

How to mitigate CVE-2026-83610

Install security update from vendor's website.

xmldom - addressed in versions 0.8.15, 0.9.12

External References

Related Security Bulletins