Vulnerabilidades em @xmldom
15 resultadosAnálise Vexday
O @xmldom apresenta um panorama de risco elevado e recente, com 15 vulnerabilidades identificadas nos últimos 90 dias, concentradas predominantemente em processamento inseguro de XML (CWE-91). Embora nenhuma esteja atualmente sob ataque ativo registrado ou classificada como crítica, a concentração temporal de descobertas sugere ciclo ativo de pesquisa de segurança que demanda análise e remediação prioritária.
CVE-2026-83610MEDIUMxmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serializationEPSS 0.4%CVE-2026-83611MEDIUMxmldom: Parser silently accepts a not-well-formed end tag whose name is followed by a line break and trailing contentEPSS 0.4%CVE-2026-83615HIGHxmldom: Quadratic-memory consumptionEPSS 0.4%CVE-2026-83614HIGHxmldom: Quadratic-time parsing via the malformed-input recovery path — `parseElementStartPart` re-scan and `normalize()` adjacent-text mergeEPSS 0.4%CVE-2026-83605HIGHxmldom: Attribute name injection via setAttribute() bypasses requireWellFormedEPSS 0.3%CVE-2026-83608HIGHxmldom: DocType `name` Injection Bypasses requireWellFormedEPSS 0.3%CVE-2026-83616HIGHxmldom: Processing Instruction Target Injection Bypasses requireWellFormedEPSS 0.3%CVE-2026-83607HIGHxmldom: Element name injection via createElement() bypasses requireWellFormedEPSS 0.3%CVE-2026-83613HIGHxmldom: Quadratic-time attribute deduplicationEPSS 0.3%CVE-2026-83618HIGHxmldom: requireWellFormed DocType publicId/systemId validation is bypassable via an embedded line terminatorEPSS 0.3%CVE-2026-83617HIGHxmldom: requireWellFormed element/attribute name validation is bypassable via an embedded line terminatorEPSS 0.3%CVE-2026-83609HIGHxmldom: Creation-time XML Name/QName validation is bypassable via an embedded line terminator, allowing injection on the default serialization pathEPSS 0.3%CVE-2026-83619HIGHxmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parserEPSS 0.3%CVE-2026-83612HIGHxmldom: HTML raw-text closing-tag case mismatch causes output amplificationEPSS 0.3%CVE-2026-83606HIGHxmldom PI grammar regex ReDoS: quadratic backtracking on unterminated processing instructionsEPSS 0.3%