CVE-2026-83608

Source
https://cve.org/CVERecord?id=CVE-2026-83608
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-83608.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-83608
Aliases
  • GHSA-27p8-2357-5qqv
Downstream
Published
2026-09-01T14:27:26.057Z
Modified
2026-09-03T03:48:07.140770619Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
xmldom: DocType `name` Injection Bypasses requireWellFormed
Details

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, the DOCUMENTTYPENODE branch in lib/dom.js validates publicId, systemId, and internalSubset under requireWellFormed: true but emits DocumentType.name verbatim. A name containing > or whitespace can terminate the

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/83xxx/CVE-2026-83608.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-91"
    ]
}
References

Affected packages

Git / github.com/xmldom/xmldom

Affected ranges

Type
GIT
Repo
https://github.com/xmldom/xmldom
Events
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "0.6.0"
        },
        {
            "introduced": "0.9.0"
        },
        {
            "fixed": "0.9.12"
        },
        {
            "introduced": "0.7.0"
        },
        {
            "fixed": "0.8.15"
        }
    ]
}

Affected versions

0.*
0.7.0
0.7.0+scoped
0.7.0+unscoped
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.14
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.10
0.9.11
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
v0.*
v0.7.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-83608.json"