๐Ÿ” CVE Alert

CVE-2026-83617

UNKNOWN 0.0

xmldom: requireWellFormed element/attribute name validation is bypassable via an embedded line terminator

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.11 until 0.9.12, the requireWellFormed: true element and attribute name checks use the anchored QName_exact expression produced by reg() in lib/grammar.js, which inherits the multiline flag. A name with a valid first line followed by U+000A, U+000D, U+2028, or U+2029 and breakout markup therefore passes validation and is emitted verbatim in element start and end tags or attribute names. This bypasses the strict-serialization checks introduced for the earlier element-name and attribute-name injection advisories, while the default serialization path remains outside the strict guarantee. This issue is fixed in @xmldom/xmldom version 0.9.12.

CWE CWE-91 CWE-625
Vendor xmldom
Product xmldom
Published Sep 1, 2026
Last Updated Sep 1, 2026
Stay Ahead of the Next One

Get instant alerts for xmldom xmldom

Be the first to know when new unknown vulnerabilities affecting xmldom xmldom are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

xmldom / xmldom
>= 0.9.11, < 0.9.12
@xmldom / xmldom
>= 0.9.11, < 0.9.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/xmldom/xmldom/security/advisories/GHSA-jxjr-3g7g-3944 github.com: https://github.com/xmldom/xmldom/pull/1071 github.com: https://github.com/xmldom/xmldom/commit/7b2ec67e1750daadd0bb06c92e875e726544a362 github.com: https://github.com/xmldom/xmldom/releases/tag/0.9.12