@xmldom/xmldom vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-83616High@xmldom/xmldom: xmldom: Processing Instruction Target Injection Bypasses requireWellFormedCVE-2026-83617High@xmldom/xmldom: xmldom: requireWellFormed element/attribute name validation is bypassable via an embedded line terminatorCVE-2026-83608High@xmldom/xmldom: xmldom: DocType `name` Injection Bypasses requireWellFormedCVE-2026-83609High@xmldom/xmldom: xmldom: Creation-time XML Name/QName validation is bypassable via an embedded line terminator, allowing injection on the default…CVE-2026-83618High@xmldom/xmldom: xmldom: requireWellFormed DocType publicId/systemId validation is bypassable via an embedded line terminatorCVE-2026-83611Medium@xmldom/xmldom: xmldom: Parser silently accepts a not-well-formed end tag whose name is followed by a line break and trailing contentCVE-2026-83613High@xmldom/xmldom: xmldom: Quadratic-time attribute deduplicationCVE-2026-83619High@xmldom/xmldom: xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parserCVE-2026-83615High@xmldom/xmldom: xmldom: Quadratic-memory consumptionCVE-2026-83614High@xmldom/xmldom: xmldom: Quadratic-time parsing via the malformed-input recovery path — `parseElementStartPart` re-scan and `normalize()` adjacent-text mergeCVE-2026-83612High@xmldom/xmldom: xmldom: HTML raw-text closing-tag case mismatch causes output amplificationCVE-2026-83606High@xmldom/xmldom: xmldom PI grammar regex ReDoS: quadratic backtracking on unterminated processing instructionsCVE-2026-83607High@xmldom/xmldom: xmldom: Element name injection via createElement() bypasses requireWellFormedCVE-2026-83605High@xmldom/xmldom: xmldom: Attribute name injection via setAttribute() bypasses requireWellFormedCVE-2026-83610Medium@xmldom/xmldom: xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serializationCVE-2026-41673High@xmldom/xmldom: xmldom: Uncontrolled recursion in XML serialization leads to DoSCVE-2026-41674High@xmldom/xmldom: xmldom has XML injection through unvalidated DocumentType serializationCVE-2026-41675High@xmldom/xmldom: xmldom has XML node injection through unvalidated processing instruction serializationCVE-2026-41672High@xmldom/xmldom: xmldom has XML node injection through unvalidated comment serializationCVE-2026-34601Highxmldom: xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertionCVE-2022-39353Criticalxmldom: xmldom allows multiple root nodes in a DOMCVE-2021-32796Mediumxmldom: Misinterpretation of malicious XML input

Stop the waste.
Protect your environment with Kodem.