Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

14 advisories

Loading
xmldom: Processing Instruction Target Injection Bypasses requireWellFormed High
CVE-2026-83616 was published for @xmldom/xmldom (npm) Sep 8, 2026
bhaswanthc Credited to bhaswanthc and arpitjain099 arpitjain099 arpitjain099
karfau Credited to karfau
xmldom: DocType `name` Injection Bypasses requireWellFormed High
CVE-2026-83608 was published for @xmldom/xmldom (npm) Sep 8, 2026
karfau Credited to karfau
karfau Credited to karfau
xmldom: Element name injection via createElement() bypasses requireWellFormed High
CVE-2026-83607 was published for @xmldom/xmldom (npm) Sep 8, 2026
bhaswanthc Credited to bhaswanthc
xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed High
CVE-2026-83605 was published for @xmldom/xmldom (npm) Sep 8, 2026
bhaswanthc Credited to bhaswanthc
samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Assertions High
CVE-2026-46490 was published for samlify (npm) May 21, 2026
RootUp Credited to RootUp
fast-xml-builder allows attribute values with unwanted quotes to bypass malicious or unwanted attributes High
CVE-2026-44665 was published for fast-xml-builder (npm) May 8, 2026
amitguptagwl Credited to amitguptagwl
xmldom has XML injection through unvalidated DocumentType serialization High
CVE-2026-41674 was published for @xmldom/xmldom (npm) Apr 22, 2026
TharVid Credited to TharVid
xmldom has XML node injection through unvalidated processing instruction serialization High
CVE-2026-41675 was published for @xmldom/xmldom (npm) Apr 22, 2026
tlsbollei Credited to tlsbollei and TharVid TharVid TharVid
xmldom has XML node injection through unvalidated comment serialization High
CVE-2026-41672 was published for @xmldom/xmldom (npm) Apr 22, 2026
Jvr2022 Credited to Jvr2022 and TharVid TharVid TharVid
xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion High
CVE-2026-34601 was published for @xmldom/xmldom (npm) Apr 1, 2026
thesmartshadow Credited to thesmartshadow and karfau karfau karfau
eoftedal Credited to eoftedal
ProTip! Advisories are also available from the GraphQL API