Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-34601

Опубликовано: 02 апр. 2026
Источник: redhat
CVSS3: 7.5

Описание

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. In xmldom versions 0.6.0 and prior and @xmldom/xmldom prior to versions 0.8.12 and 0.9.9, xmldom/xmldom allows attacker-controlled strings containing the CDATA terminator ]]> to be inserted into a CDATASection node. During serialization, XMLSerializer emitted the CDATA content verbatim without rejecting or safely splitting the terminator. As a result, data intended to remain text-only became active XML markup in the serialized output, enabling XML structure injection and downstream business-logic manipulation. This issue has been patched in xmldom version 0.6.0 and @xmldom/xmldom versions 0.8.12 and 0.9.9.

A flaw was found in xmldom. A remote attacker can exploit this by inserting specific character sequences, known as the CDATA (Character Data) terminator ]]>, into a CDATASection node. When the XML is serialized, these sequences are not properly handled, allowing them to be interpreted as active XML markup. This vulnerability enables XML structure injection, which could lead to manipulation of the XML data and affect business logic.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Applications 8redhat-user-workloads/art-imagesNot affected
Red Hat Build of Podman Desktoppodman-desktop-macos-1-0Not affected
Red Hat Build of Podman Desktoppodman-desktop-windows-1-0Not affected
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Not affected
Red Hat Fuse 7xmldomNot affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mlflow-rhel9Not affected
Red Hat OpenShift Container Platform 4redhat-user-workloads/art-imagesNot affected
Red Hat OpenShift Dev Spacesredhat-user-workloads/code-rhel9Not affected
Self-service automation portal 2redhat-user-workloads/ansible-pluginsNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-91
https://bugzilla.redhat.com/show_bug.cgi?id=2454595xmldom: xmldom: XML structure injection via CDATA terminator

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In xmldom versions 0.6.0 and prior and @xmldom/xmldom prior to versions 0.8.12 and 0.9.9, xmldom/xmldom allows attacker-controlled strings containing the CDATA terminator ]]> to be inserted into a CDATASection node. During serialization, XMLSerializer emitted the CDATA content verbatim without rejecting or safely splitting the terminator. As a result, data intended to remain text-only became active XML markup in the serialized output, enabling XML structure injection and downstream business-logic manipulation. This issue has been patched in xmldom version 0.6.0 and @xmldom/xmldom versions 0.8.12 and 0.9.9.

CVSS3: 7.5
nvd
4 месяца назад

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In xmldom versions 0.6.0 and prior and @xmldom/xmldom prior to versions 0.8.12 and 0.9.9, xmldom/xmldom allows attacker-controlled strings containing the CDATA terminator ]]> to be inserted into a CDATASection node. During serialization, XMLSerializer emitted the CDATA content verbatim without rejecting or safely splitting the terminator. As a result, data intended to remain text-only became active XML markup in the serialized output, enabling XML structure injection and downstream business-logic manipulation. This issue has been patched in xmldom version 0.6.0 and @xmldom/xmldom versions 0.8.12 and 0.9.9.

msrc
4 месяца назад

xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion

CVSS3: 7.5
debian
4 месяца назад

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) ...

CVSS3: 7.5
github
4 месяца назад

xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion

7.5 High

CVSS3