Improper Encoding or Escaping of Output in xmldom - CVE-2026-83610
Published: August 25, 2026 / Updated: September 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to inject XML markup into serialized output.
The vulnerability exists due to improper encoding or escaping of output in the XML serializer ENTITY_REFERENCE_NODE serialization path when serializing an EntityReference node with requireWellFormed enabled. A remote attacker can supply an invalid EntityReference name to inject XML markup into serialized output.
The main affected scenario is applications that directly create an EntityReference from attacker-controlled input and later reparse the serialized fragment in an XML context.