SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-83609

HIGH · CVSS 8.7 EPSS 0.33% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The xmldom module in JavaScript versions 0.9.0 to 0.9.12 is vulnerable to XML injection due to improper validation of XML names, allowing attackers to craft malformed XML that can lead to markup injection during serialization. This vulnerability poses a high risk, as it can be exploited to manipulate XML data structures, potentially compromising application integrity. Organizations using affected versions of xmldom should prioritize upgrading to version 0.9.12 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-83609
Severity
HIGH
CVSS
8.7
EPSS
0.33%
Java

Original NVD Description

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0 until 0.9.12, the shared reg() builder in lib/grammar.js compiles the anchored QName_exact validator with the multiline flag, so ^ and $ validate only one line instead of the complete name. createElementNS, createAttributeNS, createDocumentType, and createAttribute consequently accept a malformed XML name whose first line is valid and whose later text injects markup when serialized through either the default path or requireWellFormed: true. The triggering ECMAScript line terminators are U+000A, U+000D, U+2028, and U+2029. This issue is fixed in @xmldom/xmldom version 0.9.12.