XML injection in xmldom - CVE-2026-83616

 

XML injection in xmldom - CVE-2026-83616

Published: August 25, 2026 / Updated: September 2, 2026


Vulnerability identifier: #VU145138
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-83616
CWE-ID: CWE-91
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to inject arbitrary XML content into serialized output.

The vulnerability exists due to xml injection in Document.createProcessingInstruction() and the XML serializer when processing user-controlled processing-instruction target values during serialization. A remote attacker can supply a specially crafted target string to inject arbitrary XML content into serialized output.

If the serialized output is later processed as XHTML by a browser, injected script elements may execute. Exploitation requires application code to create processing instructions from untrusted target input and serialize the resulting document.


Affected software

xmldom
IBM DataPower Gateway

How to mitigate CVE-2026-83616

Install security update from vendor's website.

xmldom - addressed in versions 0.8.15, 0.9.12
IBM DataPower Gateway - addressed in versions 10.5.0.23, 10.6.0.11, 11.0.0.3

External References

Related Security Bulletins