Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 01 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xmldom
Xmldom xmldom |
|
| Vendors & Products |
Xmldom
Xmldom xmldom |
|
| Metrics |
ssvc
|
Tue, 01 Sep 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.11 until 0.9.12, the requireWellFormed: true element and attribute name checks use the anchored QName_exact expression produced by reg() in lib/grammar.js, which inherits the multiline flag. A name with a valid first line followed by U+000A, U+000D, U+2028, or U+2029 and breakout markup therefore passes validation and is emitted verbatim in element start and end tags or attribute names. This bypasses the strict-serialization checks introduced for the earlier element-name and attribute-name injection advisories, while the default serialization path remains outside the strict guarantee. This issue is fixed in @xmldom/xmldom version 0.9.12. | |
| Title | xmldom: requireWellFormed element/attribute name validation is bypassable via an embedded line terminator | |
| Weaknesses | CWE-625 CWE-91 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-01T15:30:45.725Z
Reserved: 2026-08-31T20:36:25.744Z
Link: CVE-2026-83617
Updated: 2026-09-01T15:30:42.162Z
Status : Received
Published: 2026-09-01T15:17:40.273
Modified: 2026-09-01T16:17:28.103
Link: CVE-2026-83617
No data.
OpenCVE Enrichment
Updated: 2026-09-01T17:00:17Z