XML injection in xmldom - CVE-2026-83616
Published: August 25, 2026 / Updated: September 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to inject arbitrary XML content into serialized output.
The vulnerability exists due to xml injection in Document.createProcessingInstruction() and the XML serializer when processing user-controlled processing-instruction target values during serialization. A remote attacker can supply a specially crafted target string to inject arbitrary XML content into serialized output.
If the serialized output is later processed as XHTML by a browser, injected script elements may execute. Exploitation requires application code to create processing instructions from untrusted target input and serialize the resulting document.
Affected software
IBM DataPower Gateway
How to mitigate CVE-2026-83616
IBM DataPower Gateway - addressed in versions 10.5.0.23, 10.6.0.11, 11.0.0.3