CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-83609

highcovered by 2 sourcesfirst seen 2026-09-01
Summary An embedded line terminator bypasses xmldom's always-on, WHATWG-mandated creation-time name validation. createElementNS, createAttributeNS, createDocumentType, and createAttribute should reject a malformed qualified name with InvalidCharacterError, but a name whose first line is well-formed slips through and enters the DOM. On serialization it is emitted verbatim, so the characters after the line terminator inject markup into the output. The injection reaches the default serialization path, and enabling requireWellFormed does not prevent it. Details createElementNS, createAttributeNS, and createDocumentType route through validateQualifiedName, and createAttribute performs the analogous check; each validates the name with g.QName_exact.test(name). QName_exact = reg('^', QName, '$') inherits the m flag from xmldom's shared regexp builder, so the matcher accepts any name whose first line is a valid QName and leaves the remaining lines unconstrained (see Root Cause). Root Cause 1. A shared regexp builder compiles anchored productions with the m flag. 2. ^…$ under m are line anchors, not string anchors. 3. validateQualifiedName / createAttribute validate with .test() against such a production, so a line terminator followed by breakout markup passes and the malformed name is stored. The triggering line terminators are the ECMAScript LineTerminator set: U+000A, U+000D, U+2028, U+2029. Proof of Concept const { DOMImplementation, XMLSerializer } = require('@xmldom/xmldom'); const impl = new DOMImplementation(); const doc = impl.createDocument('urn:x', 'root', null); const el = doc.createElementNS('urn:x', 'a\n><script>x</script'); // ACCEPTED (no throw) doc.documentElement.appendChild(el); // DEFAULT serialization — requireWellFormed NOT set: console.log(new XMLSerializer().serializeToString(doc)); // Observed: <root xmlns="urn:x"><a // ><script>x</script/></root> <-- injected element on the default path // Control: createElementNS('urn:x', 'bad>name') thro

⚡ Watch CVE-2026-83609

Get an email if CVE-2026-83609 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-83609

CVE.org record

Embed the live status

CVE-2026-83609 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-83609 status](https://www.csirts.com/badge/CVE-2026-83609)](https://www.csirts.com/cve/CVE-2026-83609)