CVE-2026-41674

EUVD-2026-28289
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, the package serializes DocumentType node fields (internalSubset, publicId, systemId) verbatim without any escaping or validation. When these fields are set programmatically to attacker-controlled strings, XMLSerializer.serializeToString can produce output where the DOCTYPE declaration is terminated early and arbitrary markup appears outside it. This issue has been patched in versions @xmldom/xmldom versions 0.9.10 and 0.8.13.
aka Blind XPath Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 37.41%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat Developer Hub 1.8
1779841586 ≤
𝑥
< *
ADP
Red HatRed Hat Developer Hub 1.9
1781187342 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.20
1779864090 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.21
1779252093 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
node-xmldom
bookworm
no-dsa
bullseye
postponed
forky
0.9.10-2
fixed
sid
0.9.10-2
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
node-xmldom
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage