Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-83617

Опубликовано: 01 сент. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.11 until 0.9.12, the requireWellFormed: true element and attribute name checks use the anchored QName_exact expression produced by reg() in lib/grammar.js, which inherits the multiline flag. A name with a valid first line followed by U+000A, U+000D, U+2028, or U+2029 and breakout markup therefore passes validation and is emitted verbatim in element start and end tags or attribute names. This bypasses the strict-serialization checks introduced for the earlier element-name and attribute-name injection advisories, while the default serialization path remains outside the strict guarantee. This issue is fixed in @xmldom/xmldom version 0.9.12.

A flaw was found in the @xmldom/xmldom library. The requireWellFormed validation for XML element and attribute names can be bypassed by embedding specific line terminator characters. This allows an attacker to inject malformed XML into the document, potentially leading to XML injection vulnerabilities and bypassing security checks designed to prevent such issues.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Build of Podman Desktoprh-podman-desktop.gitAffected
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Not affected
Red Hat Enterprise Linux 10grafanaAffected
Red Hat Enterprise Linux 8grafanaAffected
Red Hat Enterprise Linux 9grafanaAffected
Red Hat Fuse 7xmldomAffected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mlflow-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-91
https://bugzilla.redhat.com/show_bug.cgi?id=2526848@xmldom/xmldom: xmldom: XML injection via embedded line terminator in element/attribute names

EPSS

Процентиль: 26%
0.00328
Низкий

7.5 High

CVSS3

Связанные уязвимости

ubuntu
18 дней назад

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.11 until 0.9.12, the requireWellFormed: true element and attribute name checks use the anchored QName_exact expression produced by reg() in lib/grammar.js, which inherits the multiline flag. A name with a valid first line followed by U+000A, U+000D, U+2028, or U+2029 and breakout markup therefore passes validation and is emitted verbatim in element start and end tags or attribute names. This bypasses the strict-serialization checks introduced for the earlier element-name and attribute-name injection advisories, while the default serialization path remains outside the strict guarantee. This issue is fixed in @xmldom/xmldom version 0.9.12.

nvd
18 дней назад

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.11 until 0.9.12, the requireWellFormed: true element and attribute name checks use the anchored QName_exact expression produced by reg() in lib/grammar.js, which inherits the multiline flag. A name with a valid first line followed by U+000A, U+000D, U+2028, or U+2029 and breakout markup therefore passes validation and is emitted verbatim in element start and end tags or attribute names. This bypasses the strict-serialization checks introduced for the earlier element-name and attribute-name injection advisories, while the default serialization path remains outside the strict guarantee. This issue is fixed in @xmldom/xmldom version 0.9.12.

debian
18 дней назад

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) ...

github
11 дней назад

xmldom: requireWellFormed element/attribute name validation is bypassable via an embedded line terminator

CVSS3: 7.5
fstec
29 дней назад

Уязвимость функции reg() файла lib/grammar.js модуля определения способа доступа к документам XML и управления ими XMLDOM, позволяющая нарушителю обойти существующие механизмы безопасности

EPSS

Процентиль: 26%
0.00328
Низкий

7.5 High

CVSS3