THREAT OPS › Threat News › [GHSA] GHSA-3px3-54cx-rmw9 (high) — xmldom: Creation-time XML Name/QName validation is bypassable via an embedded line terminator, allowing injection on the default serialization path
[GHSA] GHSA-3px3-54cx-rmw9 (high) — xmldom: Creation-time XML Name/QName validation is bypassable via an embedded line terminator, allowing injection on the default serialization path
GHSA-3px3-54cx-rmw9 Severity: high CVE: CVE-2026-83609
xmldom: Creation-time XML Name/QName validation is bypassable via an embedded line terminator, allowing injection on the default serialization path
## Summary
An embedded line terminator bypasses xmldom's always-on, WHATWG-mandated creation-time name validation. `createElementNS`, `createAttributeNS`, `createDocumentType`, and `createAttrib
Indicators of compromise
- CVE-2026-83609cve
Original source: https://github.com/advisories/GHSA-3px3-54cx-rmw9