{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-41672", "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa", "state": "PUBLISHED", "assignerShortName": "GitHub_M", "dateReserved": "2026-04-22T03:53:24.405Z", "datePublished": "2026-05-07T03:36:16.914Z", "dateUpdated": "2026-07-15T00:58:53.185Z" }, "containers": { "cna": { "title": "xmldom: XML node injection through unvalidated comment serialization", "problemTypes": [ { "descriptions": [ { "cweId": "CWE-91", "lang": "en", "description": "CWE-91: XML Injection (aka Blind XPath Injection)", "type": "CWE" } ] } ], "metrics": [ { "cvssV4_0": { "attackVector": "NETWORK", "attackComplexity": "LOW", "attackRequirements": "NONE", "privilegesRequired": "NONE", "userInteraction": "NONE", "vulnConfidentialityImpact": "NONE", "vulnIntegrityImpact": "HIGH", "vulnAvailabilityImpact": "NONE", "subConfidentialityImpact": "NONE", "subIntegrityImpact": "NONE", "subAvailabilityImpact": "NONE", "baseScore": 8.7, "baseSeverity": "HIGH", "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N", "version": "4.0" } } ], "references": [ { "name": "https://github.com/xmldom/xmldom/security/advisories/GHSA-j759-j44w-7fr8", "tags": [ "x_refsource_CONFIRM" ], "url": "https://github.com/xmldom/xmldom/security/advisories/GHSA-j759-j44w-7fr8" }, { "name": "https://github.com/xmldom/xmldom/pull/987", "tags": [ "x_refsource_MISC" ], "url": "https://github.com/xmldom/xmldom/pull/987" }, { "name": "https://github.com/xmldom/xmldom/commit/b397540889086da868c30c366ad5c220d1a750c7", "tags": [ "x_refsource_MISC" ], "url": "https://github.com/xmldom/xmldom/commit/b397540889086da868c30c366ad5c220d1a750c7" }, { "name": "https://github.com/xmldom/xmldom/commit/fda7cc313de30243fea35cada64e0bb12099c2a1", "tags": [ "x_refsource_MISC" ], "url": "https://github.com/xmldom/xmldom/commit/fda7cc313de30243fea35cada64e0bb12099c2a1" }, { "name": "https://github.com/xmldom/xmldom/releases/tag/0.8.13", "tags": [ "x_refsource_MISC" ], "url": "https://github.com/xmldom/xmldom/releases/tag/0.8.13" }, { "name": "https://github.com/xmldom/xmldom/releases/tag/0.9.10", "tags": [ "x_refsource_MISC" ], "url": "https://github.com/xmldom/xmldom/releases/tag/0.9.10" } ], "affected": [ { "vendor": "xmldom", "product": "xmldom", "versions": [ { "version": "xmldom <= 0.6.0", "status": "affected" }, { "version": "@xmldom/xmldom >= 0.9.0, < 0.9.10", "status": "affected" }, { "version": "@xmldom/xmldom < 0.8.13", "status": "affected" } ] } ], "providerMetadata": { "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa", "shortName": "GitHub_M", "dateUpdated": "2026-05-07T03:36:16.914Z" }, "descriptions": [ { "lang": "en", "value": "xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, the package allows attacker-controlled comment content to be serialized into XML without validating or neutralizing comment-breaking sequences. As a result, an attacker can terminate the comment early and inject arbitrary XML nodes into the serialized output. This issue has been patched in versions @xmldom/xmldom versions 0.9.10 and 0.8.13." } ], "source": { "advisory": "GHSA-j759-j44w-7fr8", "discovery": "UNKNOWN" } }, "adp": [ { "references": [ { "url": "https://github.com/xmldom/xmldom/security/advisories/GHSA-j759-j44w-7fr8", "tags": [ "exploit" ] } ], "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-05-07T14:11:04.312092Z", "id": "CVE-2026-41672", "options": [ { "Exploitation": "poc" }, { "Automatable": "yes" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-05-07T14:58:08.512Z" } }, { "affected": [ { "collectionURL": "https://catalog.redhat.com/software/containers/", "cpes": [ "cpe:/a:redhat:rhdh:1.9::el9" ], "defaultStatus": "affected", "packageName": "rhdh/rhdh-hub-rhel9", "product": "Red Hat Developer Hub 1.9", "vendor": "Red Hat", "versions": [ { "lessThan": "*", "status": "unaffected", "version": "1781187342", "versionType": "rpm" } ] }, { "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": [ "cpe:/a:redhat:podman_desktop:1" ], "defaultStatus": "affected", "packageName": "rh-podman-desktop.git", "product": "Red Hat Build of Podman Desktop", "vendor": "Red Hat" }, { "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": [ "cpe:/o:redhat:enterprise_linux:8" ], "defaultStatus": "unaffected", "packageName": "grafana", "product": "Red Hat Enterprise Linux 8", "vendor": "Red Hat" }, { "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": [ "cpe:/a:redhat:jboss_fuse:7" ], "defaultStatus": "affected", "packageName": "xmldom", "product": "Red Hat Fuse 7", "vendor": "Red Hat" }, { "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": [ "cpe:/a:redhat:openshift_ai" ], "defaultStatus": "unaffected", "packageName": "rhoai/odh-mlflow-rhel9", "product": "Red Hat OpenShift AI (RHOAI)", "vendor": "Red Hat" }, { "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": [ "cpe:/a:redhat:openshift_ai" ], "defaultStatus": "affected", "packageName": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9", "product": "Red Hat OpenShift AI (RHOAI)", "vendor": "Red Hat" }, { "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": [ "cpe:/a:redhat:openshift:4" ], "defaultStatus": "unaffected", "packageName": "openshift4/ose-agent-installer-ui-rhel9", "product": "Red Hat OpenShift Container Platform 4", "vendor": "Red Hat" }, { "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": [ "cpe:/a:redhat:openshift:4" ], "defaultStatus": "affected", "packageName": "openshift4/ose-console", "product": "Red Hat OpenShift Container Platform 4", "vendor": "Red Hat" }, { "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": [ "cpe:/a:redhat:ansible_portal:2" ], "defaultStatus": "affected", "packageName": "ansible-automation-platform/automation-portal", "product": "Self-service automation portal 2", "vendor": "Red Hat" } ], "datePublic": "2026-05-07T03:36:16.914Z", "descriptions": [ { "lang": "en", "value": "A flaw was found in xmldom and @xmldom/xmldom, a JavaScript module for parsing and serializing XML. This vulnerability allows an attacker to inject malicious content into XML comments. By doing so, the attacker can prematurely close a comment and insert unauthorized XML elements into the final output. This could lead to the manipulation of data within the XML document." } ], "metrics": [ { "other": { "content": { "namespace": "https://access.redhat.com/security/updates/classification/", "value": "Important" }, "type": "Red Hat severity rating" } }, { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", "version": "3.1" }, "format": "CVSS" } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-91", "description": "XML Injection (aka Blind XPath Injection)", "lang": "en", "type": "CWE" } ] } ], "references": [ { "tags": [ "vdb-entry", "x_refsource_REDHAT" ], "url": "https://access.redhat.com/security/cve/CVE-2026-41672" }, { "name": "RHBZ#2467631", "tags": [ "issue-tracking", "x_refsource_REDHAT" ], "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467631" }, { "tags": [ "x_sadp-csaf-vex" ], "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41672.json" }, { "tags": [ "vendor-advisory", "x_refsource_REDHAT" ], "url": "https://access.redhat.com/errata/RHSA-2026:26234" } ], "solutions": [ { "lang": "en", "value": "RHSA-2026:26234: Red Hat Developer Hub 1.9" } ], "timeline": [ { "lang": "en", "time": "2026-05-07T05:02:05.372Z", "value": "Reported to Red Hat." }, { "lang": "en", "time": "2026-05-07T03:36:16.914Z", "value": "Made public." } ], "title": "xmldom: @xmldom/xmldom: xmldom: Arbitrary XML Node Injection", "workarounds": [ { "lang": "en", "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability." } ], "x_adpType": "supplier", "x_generator": { "engine": "sadp-cli 1.0.0" }, "providerMetadata": { "orgId": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c", "shortName": "redhat-SADP", "dateUpdated": "2026-07-15T00:58:53.185Z" } } ] } }