cbcvebase.
CVE-2026-34601
published 2026-04-02

CVE-2026-34601: xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In xmldom versions 0.6.0 and prior and…

PriorityP348high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.47%
37.7th percentile
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In xmldom versions 0.6.0 and prior and @xmldom/xmldom prior to versions 0.8.12 and 0.9.9, xmldom/xmldom allows attacker-controlled strings containing the CDATA terminator ]]> to be inserted into a CDATASection node. During serialization, XMLSerializer emitted the CDATA content verbatim without rejecting or safely splitting the terminator. As a result, data intended to remain text-only became active XML markup in the serialized output, enabling XML structure injection and downstream business-logic manipulation. This issue has been patched in xmldom version 0.6.0 and @xmldom/xmldom versions 0.8.12 and 0.9.9.

Affected

11 ranges
VendorProductVersion rangeFixed in
debiannode-xmldom< node-xmldom 0.9.9-1 (forky)node-xmldom 0.9.9-1 (forky)
msrcazl3_python-tensorboard_2.16.2-6_on_azure_linux_3.0
msrccbl2_python-tensorboard_2.11.0-3_on_cbl_mariner_2.0
xmldomxmldom
xmldomxmldom
xmldomxmldom
xmldomxmldom>= 0 < 0.8.120.8.12
xmldomxmldom>= 0 < 0.8.130.8.13
xmldomxmldom0 – 0.6.0
xmldomxmldom>= 0.9.0 < 0.9.90.9.9
xmldomxmldom>= 0.9.0 < 0.9.100.9.10

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
ghsa7.5HIGH
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.