Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41672

Опубликовано: 07 мая 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, the package allows attacker-controlled comment content to be serialized into XML without validating or neutralizing comment-breaking sequences. As a result, an attacker can terminate the comment early and inject arbitrary XML nodes into the serialized output. This issue has been patched in versions @xmldom/xmldom versions 0.9.10 and 0.8.13.

A flaw was found in xmldom and @xmldom/xmldom, a JavaScript module for parsing and serializing XML. This vulnerability allows an attacker to inject malicious content into XML comments. By doing so, the attacker can prematurely close a comment and insert unauthorized XML elements into the final output. This could lead to the manipulation of data within the XML document.

Отчет

This flaw is rated as Important. The xmldom JavaScript module, used in various Red Hat products, is vulnerable to arbitrary XML node injection. An attacker can craft malicious XML comments to prematurely terminate a comment block and insert unauthorized XML elements, leading to data manipulation within the processed XML document. This risk is present in applications that handle and serialize untrusted XML input.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Build of Podman Desktoprh-podman-desktop.gitAffected
Red Hat Enterprise Linux 8grafanaNot affected
Red Hat Fuse 7xmldomWill not fix
Red Hat OpenShift AI (RHOAI)rhoai/odh-mlflow-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9Affected
Red Hat OpenShift Container Platform 4openshift4/ose-agent-installer-ui-rhel9Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-consoleAffected
Self-service automation portal 2ansible-automation-platform/automation-portalAffected
Red Hat Developer Hub 1.9rhdh/rhdh-hub-rhel9FixedRHSA-2026:2623416.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-91
https://bugzilla.redhat.com/show_bug.cgi?id=2467631xmldom: @xmldom/xmldom: xmldom: Arbitrary XML Node Injection

EPSS

Процентиль: 29%
0.00365
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, the package allows attacker-controlled comment content to be serialized into XML without validating or neutralizing comment-breaking sequences. As a result, an attacker can terminate the comment early and inject arbitrary XML nodes into the serialized output. This issue has been patched in versions @xmldom/xmldom versions 0.9.10 and 0.8.13.

CVSS3: 7.5
nvd
3 месяца назад

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, the package allows attacker-controlled comment content to be serialized into XML without validating or neutralizing comment-breaking sequences. As a result, an attacker can terminate the comment early and inject arbitrary XML nodes into the serialized output. This issue has been patched in versions @xmldom/xmldom versions 0.9.10 and 0.8.13.

msrc
3 месяца назад

xmldom: XML node injection through unvalidated comment serialization

CVSS3: 7.5
debian
3 месяца назад

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) ...

github
4 месяца назад

xmldom has XML node injection through unvalidated comment serialization

EPSS

Процентиль: 29%
0.00365
Низкий

7.5 High

CVSS3