๐Ÿ” CVE Alert

CVE-2026-83618

UNKNOWN 0.0

xmldom: requireWellFormed DocType publicId/systemId validation is bypassable via an embedded line terminator

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.10 until 0.9.12, the requireWellFormed: true serializer validates DocumentType.publicId and DocumentType.systemId with PubidLiteral_match and SystemLiteral_match expressions produced by reg() in lib/grammar.js, which inherit the multiline flag. A complete valid literal on the first line can therefore satisfy the matcher while U+000A, U+000D, U+2028, or U+2029 and breakout markup remain in the emitted <!DOCTYPE ...> declaration. This bypasses the strict-serialization mitigation for the earlier DocumentType injection advisory; creation and direct property assignment remain unvalidated by design. This issue is fixed in @xmldom/xmldom version 0.9.12.

CWE CWE-91 CWE-625
Vendor xmldom
Product xmldom
Published Sep 1, 2026
Stay Ahead of the Next One

Get instant alerts for xmldom xmldom

Be the first to know when new unknown vulnerabilities affecting xmldom xmldom are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

xmldom / xmldom
>= 0.9.10, < 0.9.12
@xmldom / xmldom
>= 0.9.10, < 0.9.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/xmldom/xmldom/security/advisories/GHSA-vr34-hp96-76pp github.com: https://github.com/xmldom/xmldom/pull/1071 github.com: https://github.com/xmldom/xmldom/commit/7b2ec67e1750daadd0bb06c92e875e726544a362 github.com: https://github.com/xmldom/xmldom/releases/tag/0.9.12