Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. @xmldom/xmldom
  4. ›
  5. CVE-2026-83617

CVE-2026-83617: xmldom: requireWellFormed element/attribute name validation is bypassable via an embedded line terminator

September 8, 2026

An embedded line terminator bypasses the requireWellFormed serializer check for element and attribute names. The check was added to fix GHSA-w2rr-34g9-rvrj and GHSA-4w3w-2rp5-g8jm; a name whose first line is well-formed slips past it and is serialized verbatim, so the characters after the line terminator break out of the start/end tag or attribute. Callers who enabled requireWellFormed specifically to neutralize those name-injection issues remain exposed.

References

  • github.com/advisories/GHSA-jxjr-3g7g-3944
  • github.com/xmldom/xmldom/commit/7b2ec67e1750daadd0bb06c92e875e726544a362
  • github.com/xmldom/xmldom/pull/1071
  • github.com/xmldom/xmldom/releases/tag/0.9.12
  • github.com/xmldom/xmldom/security/advisories/GHSA-jxjr-3g7g-3944
  • nvd.nist.gov/vuln/detail/CVE-2026-83617

Code Behaviors & Features

Detect and mitigate CVE-2026-83617 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 0.9.11 before 0.9.12

Fixed versions

  • 0.9.12

Solution

Upgrade to version 0.9.12 or above.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Learn more about CVSS

Weakness

  • CWE-625: Permissive Regular Expression
  • CWE-91: XML Injection (aka Blind XPath Injection)

Source file

npm/@xmldom/xmldom/CVE-2026-83617.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 09 Sep 2026 00:16:27 +0000.