THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-jxjr-3g7g-3944 (high) — xmldom: requireWellFormed element/attribute name validation is bypassable via an embedded line terminator

[GHSA] GHSA-jxjr-3g7g-3944 (high) — xmldom: requireWellFormed element/attribute name validation is bypassable via an embedded line terminator

medgithub_advisoriesPublished 2026-09-08

GHSA-jxjr-3g7g-3944 Severity: high CVE: CVE-2026-83617

xmldom: requireWellFormed element/attribute name validation is bypassable via an embedded line terminator

## Summary

An embedded line terminator bypasses the `requireWellFormed` serializer check for element and attribute names. The check was added to fix GHSA-w2rr-34g9-rvrj and GHSA-4w3w-2rp5-g8jm; a name whose first line is well-formed sli

Indicators of compromise

Original source: https://github.com/advisories/GHSA-jxjr-3g7g-3944