Improper Handling of Case Sensitivity in xmldom - CVE-2026-83612
Published: August 25, 2026 / Updated: September 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of case sensitivity in the HTML raw-text parser when parsing untrusted HTML in HTML mode with mixed-case closing tags for raw-text elements. A remote attacker can send a specially crafted HTML document to cause a denial of service.
Only HTML mode is affected, and exploitation requires the application to parse and serialize untrusted text/html containing mixed-case closing tags for script, style, textarea, or title elements.