Dependency scanning
Check whether @xmldom/xmldom is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-83610
xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization
CVE-2026-34601
xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion
CVE-2026-41672
xmldom has XML node injection through unvalidated comment serialization
CVE-2026-41675
xmldom has XML node injection through unvalidated processing instruction serialization
CVE-2026-41674
xmldom has XML injection through unvalidated DocumentType serialization
CVE-2026-41673
xmldom: Uncontrolled recursion in XML serialization leads to DoS
CVE-2022-39353
xmldom allows multiple root nodes in a DOM
CVE-2021-32796
Misinterpretation of malicious XML input
CVE-2026-83613
xmldom: Quadratic-time attribute deduplication
CVE-2026-83619
xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parser
CVE-2026-83618
xmldom: requireWellFormed DocType publicId/systemId validation is bypassable via an embedded line terminator
CVE-2026-83616
xmldom: Processing Instruction Target Injection Bypasses requireWellFormed
CVE-2026-83617
xmldom: requireWellFormed element/attribute name validation is bypassable via an embedded line terminator
CVE-2026-83615
xmldom: Quadratic-memory consumption
CVE-2026-83614
xmldom: Quadratic-time parsing via the malformed-input recovery path — `parseElementStartPart` re-scan and `normalize()` adjacent-text merge
CVE-2026-83612
xmldom: HTML raw-text closing-tag case mismatch causes output amplification
CVE-2026-83611
xmldom: Parser silently accepts a not-well-formed end tag whose name is followed by a line break and trailing content
CVE-2026-83609
xmldom: Creation-time XML Name/QName validation is bypassable via an embedded line terminator, allowing injection on the default serialization path
CVE-2026-83608
xmldom: DocType `name` Injection Bypasses requireWellFormed
CVE-2026-83607
xmldom: Element name injection via createElement() bypasses requireWellFormed
CVE-2026-83605
xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed
CVE-2026-83606
xmldom PI grammar regex ReDoS: quadratic backtracking on unterminated processing instructions
CVE-2022-37616
Withdrawn: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in @xmldom/xmldom and xmldom
Browse more npm advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes