Bug 2526838 (CVE-2026-83611)
| Summary: | CVE-2026-83611 xmldom: xmldom: Malformed XML end tag parsing leads to content discard and security bypass | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | abarbaro, akhatavk, alizardo, aos-team-art-private, asdas, cdrage, dpaolell, gmalinko, janstey, jchui, jdelft, jhe, jupierce, ktsao, lchilton, lgarciaa, mbiarnes, nboldt, oaljalju, pdelbell, ppalepu, ppostler, prdhamdh, psrna, rhel-process-autobot, rstepani, rushinde, sfeifer, sghai, sidsharm, suppawar, vlaad, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in xmldom, a JavaScript XML DOM parser. The DOMParser.parseFromString() function can silently accept malformed XML end tags that include a line break and additional content. This unexpected parsing behavior causes the parser to close the element prematurely and discard the trailing content. This could potentially bypass security checks that rely on strict XML well-formedness, leading to data loss or misinterpretation in applications processing untrusted XML input.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2527561, 2527562, 2527563, 2527564, 2527566, 2527567, 2527568, 2527569 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-09-01 15:06:24 UTC
|