THREAT OPS › Threat News › [GHSA] GHSA-jxjr-3g7g-3944 (high) — xmldom: requireWellFormed element/attribute name validation is bypassable via an embedded line terminator
[GHSA] GHSA-jxjr-3g7g-3944 (high) — xmldom: requireWellFormed element/attribute name validation is bypassable via an embedded line terminator
GHSA-jxjr-3g7g-3944 Severity: high CVE: CVE-2026-83617
xmldom: requireWellFormed element/attribute name validation is bypassable via an embedded line terminator
## Summary
An embedded line terminator bypasses the `requireWellFormed` serializer check for element and attribute names. The check was added to fix GHSA-w2rr-34g9-rvrj and GHSA-4w3w-2rp5-g8jm; a name whose first line is well-formed sli
Indicators of compromise
- CVE-2026-83617cve
Original source: https://github.com/advisories/GHSA-jxjr-3g7g-3944