PatchSiren

xmldom CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH xmldom CVE published 2026-09-01

CVE-2026-83618

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-01T15:17:40.480Z and has not been modified since then. The xmldom module, a pure JavaScript implementation of the W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer, is vulnerable to a DocumentType injection attack. Versions 0.9.10 to 0.9.11 are affected. An attacker can bypass th [truncated]

HIGH xmldom CVE published 2026-09-01

CVE-2026-83615

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-01T15:17:39.887Z and has not been modified since then. The NVD entry is currently 8.7 HIGH. Organizations using xmldom in their applications should be aware of this vulnerability and take immediate action to mitigate the risk. This includes assessing their exposure, applying patches or updates, and [truncated]

HIGH xmldom CVE published 2026-09-01

CVE-2026-83613

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-01T15:17:39.583Z and has not been modified since then. The xmldom module, a pure JavaScript W3C standard-based DOMParser and XMLSerializer, is vulnerable to a performance issue that can cause Node.js event loops to stall. This occurs when parsing well-formed elements with many distinct attributes, l [truncated]

MEDIUM xmldom CVE published 2026-09-01

CVE-2026-83610

The CVE-2026-83610 issue involves a vulnerability in the xmldom module, specifically in the handling of EntityReference nodes during XML serialization. Prior to versions 0.8.15 and 0.9.12, the Document.createEntityReference(name) method accepted invalid names, and the ENTITY_REFERENCE_NODE serializer emitted the resulting nodeName directly in &name; form. This could lead to the production of attacker-cont [truncated]

HIGH xmldom CVE published 2026-09-01

CVE-2026-83608

CVE-2026-83608 is a high-severity vulnerability in the xmldom library, which is a pure JavaScript implementation of the W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. The vulnerability allows for the injection of sibling markup through the createDocumentType() function or direct DocumentType.name property write, potentially leading to security issues. The issue is fixed in @ [truncated]

HIGH xmldom CVE published 2026-09-01

CVE-2026-83605

The xmldom module, a pure JavaScript W3C standard-based DOMParser and XMLSerializer, has a vulnerability in versions prior to 0.8.14 and 0.9.11, and xmldom version 0.6.0 and earlier. This vulnerability allows for attribute name validation bypass, enabling injection of additional attributes, including event handlers, into browser-consumed output. Affected systems should be identified and patched with versi [truncated]

HIGH xmldom CVE published 2026-05-07

CVE-2026-41675

CVE-2026-41675 is a high-severity vulnerability in the xmldom package, a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. The vulnerability allows attacker-controlled processing instruction data to be serialized into XML without validating or neutralizing the PI-closing sequence ?>. This can lead to an attacker terminating the processing instruction early a [truncated]

HIGH xmldom CVE published 2026-05-07

CVE-2026-41674

The CVE-2026-41674 vulnerability affects the xmldom package, specifically versions prior to 0.9.10 and 0.8.13. This package is a pure JavaScript implementation of the W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. The vulnerability arises from the package's serialization of DocumentType node fields (internalSubset, publicId, systemId) without proper escaping or validatio [truncated]

HIGH xmldom CVE published 2026-05-07

CVE-2026-41673

CVE-2026-41673 is a high-severity vulnerability in xmldom, a JavaScript XML DOM module. Versions prior to 0.9.10 and 0.8.13 are affected, allowing for a RangeError: Maximum call stack size exceeded due to seven recursive traversals in lib/dom.js operating without a depth limit. A sufficiently deeply nested DOM tree causes the application to crash. This issue has been patched in versions @xmldom/xmldom ver [truncated]

HIGH xmldom CVE published 2026-04-02

CVE-2026-34601

CVE-2026-34601 is a HIGH severity vulnerability in xmldom, a JavaScript XML DOM module. The vulnerability allows for XML structure injection via attacker-supplied strings containing the CDATA terminator ]]> . During serialization, XMLSerializer emitted the CDATA content verbatim without rejecting or safely splitting the terminator. As a result, data intended to remain text-only became active XML markup in [truncated]