CVE-2026-83617: xmldom: requireWellFormed element/attribute name validation is bypassable via an embedded line terminator
An embedded line terminator bypasses the requireWellFormed serializer check for element and
attribute names. The check was added to fix GHSA-w2rr-34g9-rvrj and GHSA-4w3w-2rp5-g8jm; a name whose
first line is well-formed slips past it and is serialized verbatim, so the characters after the line
terminator break out of the start/end tag or attribute. Callers who enabled requireWellFormed
specifically to neutralize those name-injection issues remain exposed.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-83617 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →