THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-3px3-54cx-rmw9 (high) — xmldom: Creation-time XML Name/QName validation is bypassable via an embedded line terminator, allowing injection on the default serialization path

[GHSA] GHSA-3px3-54cx-rmw9 (high) — xmldom: Creation-time XML Name/QName validation is bypassable via an embedded line terminator, allowing injection on the default serialization path

medgithub_advisoriesPublished 2026-09-08

GHSA-3px3-54cx-rmw9 Severity: high CVE: CVE-2026-83609

xmldom: Creation-time XML Name/QName validation is bypassable via an embedded line terminator, allowing injection on the default serialization path

## Summary

An embedded line terminator bypasses xmldom's always-on, WHATWG-mandated creation-time name validation. `createElementNS`, `createAttributeNS`, `createDocumentType`, and `createAttrib

Indicators of compromise

Original source: https://github.com/advisories/GHSA-3px3-54cx-rmw9