npm

@xmldom/xmldom

View on npm registry
23 Total advisories
23 Vulnerabilities
0 Malware

Dependency scanning

Check whether @xmldom/xmldom is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

UNKNOWN
npm

CVE-2026-83610

xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization

HIGH 7.5
npm

CVE-2026-34601

xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion

UNKNOWN
npm

CVE-2026-41672

xmldom has XML node injection through unvalidated comment serialization

UNKNOWN
npm

CVE-2026-41675

xmldom has XML node injection through unvalidated processing instruction serialization

UNKNOWN
npm

CVE-2026-41674

xmldom has XML injection through unvalidated DocumentType serialization

UNKNOWN
npm

CVE-2026-41673

xmldom: Uncontrolled recursion in XML serialization leads to DoS

CRITICAL 9.8
npm

CVE-2022-39353

xmldom allows multiple root nodes in a DOM

MEDIUM 6.5
npm

CVE-2021-32796

Misinterpretation of malicious XML input

UNKNOWN
npm

CVE-2026-83613

xmldom: Quadratic-time attribute deduplication

UNKNOWN
npm

CVE-2026-83619

xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parser

UNKNOWN
npm

CVE-2026-83618

xmldom: requireWellFormed DocType publicId/systemId validation is bypassable via an embedded line terminator

UNKNOWN
npm

CVE-2026-83616

xmldom: Processing Instruction Target Injection Bypasses requireWellFormed

UNKNOWN
npm

CVE-2026-83617

xmldom: requireWellFormed element/attribute name validation is bypassable via an embedded line terminator

UNKNOWN
npm

CVE-2026-83615

xmldom: Quadratic-memory consumption

UNKNOWN
npm

CVE-2026-83614

xmldom: Quadratic-time parsing via the malformed-input recovery path — `parseElementStartPart` re-scan and `normalize()` adjacent-text merge

UNKNOWN
npm

CVE-2026-83612

xmldom: HTML raw-text closing-tag case mismatch causes output amplification

UNKNOWN
npm

CVE-2026-83611

xmldom: Parser silently accepts a not-well-formed end tag whose name is followed by a line break and trailing content

UNKNOWN
npm

CVE-2026-83609

xmldom: Creation-time XML Name/QName validation is bypassable via an embedded line terminator, allowing injection on the default serialization path

UNKNOWN
npm

CVE-2026-83608

xmldom: DocType `name` Injection Bypasses requireWellFormed

UNKNOWN
npm

CVE-2026-83607

xmldom: Element name injection via createElement() bypasses requireWellFormed

UNKNOWN
npm

CVE-2026-83605

xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed

UNKNOWN
npm

CVE-2026-83606

xmldom PI grammar regex ReDoS: quadratic backtracking on unterminated processing instructions

CRITICAL 9.8
npm

CVE-2022-37616

Withdrawn: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in @xmldom/xmldom and xmldom

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes