CVE detail
CVE-2026-41674
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, the package serializes DocumentType node fields (internalSubset, publicId, systemId) verbatim without any escaping or validation. When these fields are set programmatically to attacker-controlled strings, XMLSerializer.serializeToString can produce output where the DOCTYPE declaration is terminated early and arbitrary markup appears outside it. This issue has been patched in versions @xmldom/xmldom versions 0.9.10 and 0.8.13.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 25.6 · diversity 18.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
12 source links · newest first
Information published.
vendormsrc.microsoft.comMay 8, 2026, 8:01 AM- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41674.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comMay 7, 2026, 4:16 AM - https://bugzilla.redhat.com/show_bug.cgi?id=2467620bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comMay 7, 2026, 4:16 AM - https://access.redhat.com/security/cve/CVE-2026-41674access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 7, 2026, 4:16 AM - https://access.redhat.com/errata/RHSA-2026:26234access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 7, 2026, 4:16 AM - https://access.redhat.com/errata/RHSA-2026:21703access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 7, 2026, 4:16 AM - https://access.redhat.com/errata/RHSA-2026:21338access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 7, 2026, 4:16 AM - https://access.redhat.com/errata/RHSA-2026:20034access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 7, 2026, 4:16 AM No excerpt available.
Exploitgithub.comMay 7, 2026, 4:16 AMNo excerpt available.
Exploitgithub.comMay 7, 2026, 4:16 AMNo excerpt available.
Exploitgithub.comMay 7, 2026, 4:16 AMNo excerpt available.
Exploitgithub.comMay 7, 2026, 4:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-59728CVSS 4.3 · Medium
Astro is a web framework for content-driven websites. In versions 1.0.0 through 4.0.18, the source.title and enclosure.type item fields in packages/astro-rss/src/index.ts are inte…
- CVE-2026-15037CVSS 2.9 · Low
Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized…
- CVE-2026-55789CVSS 8.5 · High
Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's self-hosted SAML application IdP built the signed SAML response and assertion b…
- CVE-2026-53723CVSS 5.8 · Medium
Guzzle Services provides an implementation of the Guzzle Command library that uses Guzzle service descriptions to describe web services, serialize requests, and parse responses in…
- CVE-2026-46490CVSS 8.7 · High
samlify is a Node.js library for SAML single sign-on. Prior to version 2.13.0, samlify’s template substitution only escapes attribute contexts. Values inserted into element text (…
- CVE-2026-11169CVSS 8.1 · High
Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted XML file. (Chromium…