CVE-2021-21366
MEDIUMxmldom < 0.5.0 - XML Processing Syntax Manipulation via Malicious Document Parsing
Title source: llmDescription
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom versions 0.4.0 and older do not correctly preserve system identifiers, FPIs or namespaces when repeatedly parsing and serializing maliciously crafted documents. This may lead to unexpected syntactic changes during XML processing in some downstream applications. This is fixed in version 0.5.0. As a workaround downstream applications can validate the input and reject the maliciously crafted documents.
References (5)
Core 5
Core References
Mailing List, Third Party Advisory mailing-list
https://lists.debian.org/debian-lts-announce/2023/01/msg00000.html
Release Notes
https://github.com/xmldom/xmldom/releases/tag/0.5.0
Scores
CVSS v3
4.3
EPSS
0.0143
EPSS Percentile
69.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Details
CWE
CWE-115
CWE-436
Status
published
Products (3)
debian/debian_linux
10.0
npm/xmldom
0 - 0.5.0npm
xmldom_project/xmldom
< 0.5.0
Published
Mar 12, 2021
Tracked Since
Feb 18, 2026