Skip to content

pdf2json-3.1.5.tgz: 17 vulnerabilities (highest severity is: 7.5) #454

Description

@mend-for-github-com
Vulnerable Library - pdf2json-3.1.5.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /package.json

Vulnerabilities

Vulnerability Severity CVSS Dependency Type Fixed in (pdf2json version) Remediation Possible**
CVE-2026-83616 High 7.5 xmldom-0.9.7.tgz Transitive 3.1.6 ✅
CVE-2026-83615 High 7.5 xmldom-0.9.7.tgz Transitive 3.1.6 ✅
CVE-2026-83614 High 7.5 xmldom-0.9.7.tgz Transitive 3.1.6 ✅
CVE-2026-83613 High 7.5 xmldom-0.9.7.tgz Transitive 3.1.6 ✅
CVE-2026-83612 High 7.5 xmldom-0.9.7.tgz Transitive 3.1.6 ✅
CVE-2026-83609 High 7.5 xmldom-0.9.7.tgz Transitive 3.1.6 ✅
CVE-2026-83608 High 7.5 xmldom-0.9.7.tgz Transitive 3.1.6 ✅
CVE-2026-83607 High 7.5 xmldom-0.9.7.tgz Transitive 3.1.6 ✅
CVE-2026-83606 High 7.5 xmldom-0.9.7.tgz Transitive 3.1.6 ✅
CVE-2026-83605 High 7.5 xmldom-0.9.7.tgz Transitive 3.1.6 ✅
CVE-2026-41675 High 7.5 xmldom-0.9.7.tgz Transitive N/A* ❌
CVE-2026-41674 High 7.5 xmldom-0.9.7.tgz Transitive N/A* ❌
CVE-2026-41673 High 7.5 xmldom-0.9.7.tgz Transitive N/A* ❌
CVE-2026-41672 High 7.5 xmldom-0.9.7.tgz Transitive N/A* ❌
CVE-2026-34601 High 7.5 xmldom-0.9.7.tgz Transitive N/A* ❌
CVE-2026-83611 Medium 5.3 xmldom-0.9.7.tgz Transitive 3.1.6 ✅
CVE-2026-83610 Medium 5.3 xmldom-0.9.7.tgz Transitive 3.1.6 ✅

*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.

**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation

Details

CVE-2026-83616

Vulnerable Library - xmldom-0.9.7.tgz

A pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module.

Library home page: https://registry.npmjs.org/@⁠xmldom/xmldom/-/xmldom-0.9.7.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • pdf2json-3.1.5.tgz (Root Library)
    • ❌ xmldom-0.9.7.tgz (Vulnerable Library)

Found in base branch: dev

Vulnerability Details

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @⁠xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, Document.createProcessingInstruction(target, data) in lib/dom.js accepts an unvalidated target, while the requireWellFormed: true serializer checks only for a colon and the reserved case-insensitive xml name on 0.9.x and performs no target check on 0.8.x. Because serialization emits , a target containing >, ?, whitespace, or another invalid XML-name character can break the processing-instruction boundary and inject XML structure. This issue is fixed in @⁠xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.

Publish Date: 2026-09-01

URL: CVE-2026-83616

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-c7q8-3ch8-vqpv

Release Date: 2026-09-01

Fix Resolution (@⁠xmldom/xmldom): 0.9.12

Direct dependency fix Resolution (pdf2json): 3.1.6

In order to enable automatic remediation, please create workflow rules

CVE-2026-83615

Vulnerable Library - xmldom-0.9.7.tgz

A pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module.

Library home page: https://registry.npmjs.org/@⁠xmldom/xmldom/-/xmldom-0.9.7.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • pdf2json-3.1.5.tgz (Root Library)
    • ❌ xmldom-0.9.7.tgz (Vulnerable Library)

Found in base branch: dev

Vulnerability Details

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @⁠xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom versions 0.1.5 through 0.6.0, appendElement in lib/sax.js uses _copy to clone the complete currentNSMap for each nested element that declares a new namespace prefix. Keeping every ancestor map live on the parse stack creates quadratic peak namespace-map storage, so a small highly compressible XML document can exhaust the process heap before application validation. This issue is fixed in @⁠xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.

Publish Date: 2026-09-01

URL: CVE-2026-83615

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-965w-775f-mr7g

Release Date: 2026-09-01

Fix Resolution (@⁠xmldom/xmldom): 0.9.12

Direct dependency fix Resolution (pdf2json): 3.1.6

In order to enable automatic remediation, please create workflow rules

CVE-2026-83614

Vulnerable Library - xmldom-0.9.7.tgz

A pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module.

Library home page: https://registry.npmjs.org/@⁠xmldom/xmldom/-/xmldom-0.9.7.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • pdf2json-3.1.5.tgz (Root Library)
    • ❌ xmldom-0.9.7.tgz (Vulnerable Library)

Found in base branch: dev

Vulnerability Details

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @⁠xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom versions 0.3.0 through 0.6.0, two independent quadratic paths can cause denial of service. In lib/sax.js, parseElementStartPart repeatedly rescans a malformed tag name to the next > during single-character recovery; in lib/dom.js, normalize() repeatedly removes and appends adjacent text nodes, causing quadratic reindexing and string rebuilding. The first path is reachable through default DOMParser.parseFromString() processing, while the second is also reachable through a direct normalize() call on a programmatically constructed DOM, and endDocument invokes that normalization after parsing. This issue is fixed in @⁠xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.

Publish Date: 2026-09-01

URL: CVE-2026-83614

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-93r5-fhx6-vmg9

Release Date: 2026-09-01

Fix Resolution (@⁠xmldom/xmldom): 0.9.12

Direct dependency fix Resolution (pdf2json): 3.1.6

In order to enable automatic remediation, please create workflow rules

CVE-2026-83613

Vulnerable Library - xmldom-0.9.7.tgz

A pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module.

Library home page: https://registry.npmjs.org/@⁠xmldom/xmldom/-/xmldom-0.9.7.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • pdf2json-3.1.5.tgz (Root Library)
    • ❌ xmldom-0.9.7.tgz (Vulnerable Library)

Found in base branch: dev

Vulnerability Details

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @⁠xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, DOMHandler.startElement in lib/dom-parser.js inserts every parsed attribute through setAttributeNode, while NamedNodeMap.setNamedItem in lib/dom.js calls the linear getNamedItem or getNamedItemNS lookup for each insertion. A well-formed element with many distinct attributes therefore requires quadratic comparisons during DOMParser.parseFromString() and can stall a Node.js event loop before application validation. This issue is fixed in @⁠xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.

Publish Date: 2026-09-01

URL: CVE-2026-83613

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-8344-3jmq-59r6

Release Date: 2026-09-01

Fix Resolution (@⁠xmldom/xmldom): 0.9.12

Direct dependency fix Resolution (pdf2json): 3.1.6

In order to enable automatic remediation, please create workflow rules

CVE-2026-83612

Vulnerable Library - xmldom-0.9.7.tgz

A pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module.

Library home page: https://registry.npmjs.org/@⁠xmldom/xmldom/-/xmldom-0.9.7.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • pdf2json-3.1.5.tgz (Root Library)
    • ❌ xmldom-0.9.7.tgz (Vulnerable Library)

Found in base branch: dev

Vulnerability Details

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0-beta.1 until 0.9.12, HTML-mode parsing through DOMParser.parseFromString() mishandles a mixed-case closing tag for the script, style, textarea, or title raw-text elements. parseHtmlSpecialContent, selected by isHTMLRawTextElement or isHTMLEscapableRawTextElement, uses a case-sensitive indexOf() and then calls substring() with a missing-close result of negative one, causing unstable parser progression and quadratic output amplification. A small untrusted text/html document can consequently consume disproportionate CPU and memory when parsed and serialized. This issue is fixed in @⁠xmldom/xmldom version 0.9.12.

Publish Date: 2026-09-01

URL: CVE-2026-83612

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-6mj3-qw4j-hgrw

Release Date: 2026-09-01

Fix Resolution (@⁠xmldom/xmldom): 0.9.12

Direct dependency fix Resolution (pdf2json): 3.1.6

In order to enable automatic remediation, please create workflow rules

CVE-2026-83609

Vulnerable Library - xmldom-0.9.7.tgz

A pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module.

Library home page: https://registry.npmjs.org/@⁠xmldom/xmldom/-/xmldom-0.9.7.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • pdf2json-3.1.5.tgz (Root Library)
    • ❌ xmldom-0.9.7.tgz (Vulnerable Library)

Found in base branch: dev

Vulnerability Details

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0 until 0.9.12, the shared reg() builder in lib/grammar.js compiles the anchored QName_exact validator with the multiline flag, so ^ and $ validate only one line instead of the complete name. createElementNS, createAttributeNS, createDocumentType, and createAttribute consequently accept a malformed XML name whose first line is valid and whose later text injects markup when serialized through either the default path or requireWellFormed: true. The triggering ECMAScript line terminators are U+000A, U+000D, U+2028, and U+2029. This issue is fixed in @⁠xmldom/xmldom version 0.9.12.

Publish Date: 2026-09-01

URL: CVE-2026-83609

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-3px3-54cx-rmw9

Release Date: 2026-09-01

Fix Resolution (@⁠xmldom/xmldom): 0.9.12

Direct dependency fix Resolution (pdf2json): 3.1.6

In order to enable automatic remediation, please create workflow rules

CVE-2026-83608

Vulnerable Library - xmldom-0.9.7.tgz

A pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module.

Library home page: https://registry.npmjs.org/@⁠xmldom/xmldom/-/xmldom-0.9.7.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • pdf2json-3.1.5.tgz (Root Library)
    • ❌ xmldom-0.9.7.tgz (Vulnerable Library)

Found in base branch: dev

Vulnerability Details

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @⁠xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, the DOCUMENT_TYPE_NODE branch in lib/dom.js validates publicId, systemId, and internalSubset under requireWellFormed: true but emits DocumentType.name verbatim. A name containing > or whitespace can terminate the declaration and inject sibling markup; the value can be supplied through createDocumentType() on the 0.8.x and unscoped lines or through a direct DocumentType.name property write on every affected line. The default path and legacy creation-time behavior remain permissive, while the vulnerable strict path fails to enforce an XML Name. This issue is fixed in @⁠xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.

Publish Date: 2026-09-01

URL: CVE-2026-83608

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-27p8-2357-5qqv

Release Date: 2026-09-01

Fix Resolution (@⁠xmldom/xmldom): 0.9.12

Direct dependency fix Resolution (pdf2json): 3.1.6

In order to enable automatic remediation, please create workflow rules

CVE-2026-83607

Vulnerable Library - xmldom-0.9.7.tgz

A pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module.

Library home page: https://registry.npmjs.org/@⁠xmldom/xmldom/-/xmldom-0.9.7.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • pdf2json-3.1.5.tgz (Root Library)
    • ❌ xmldom-0.9.7.tgz (Vulnerable Library)

Found in base branch: dev

Vulnerability Details

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @⁠xmldom/xmldom versions 0.8.14 and 0.9.11, and in xmldom version 0.6.0 and earlier, Document.createElement(tagName) stores an unvalidated element name and XMLSerializer.serializeToString() emits that name verbatim. The requireWellFormed: true path did not validate the element qualified name or synthesized xmlns:PREFIX declaration, so attacker-controlled tag names could inject attributes, elements, or processing instructions into serialized XML or HTML and could cause cross-site scripting when browser-consumed. The unchecked values violate the XML QName constraint, and default serialization and creation-time createElement() behavior remain permissive. This issue is fixed in @⁠xmldom/xmldom versions 0.8.14 and 0.9.11; no fixed version is available for xmldom.

Publish Date: 2026-09-01

URL: CVE-2026-83607

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-w2rr-34g9-rvrj

Release Date: 2026-09-01

Fix Resolution (@⁠xmldom/xmldom): 0.9.11

Direct dependency fix Resolution (pdf2json): 3.1.6

In order to enable automatic remediation, please create workflow rules

CVE-2026-83606

Vulnerable Library - xmldom-0.9.7.tgz

A pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module.

Library home page: https://registry.npmjs.org/@⁠xmldom/xmldom/-/xmldom-0.9.7.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • pdf2json-3.1.5.tgz (Root Library)
    • ❌ xmldom-0.9.7.tgz (Vulnerable Library)

Found in base branch: dev

Vulnerability Details

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0-beta.9 until 0.9.11, the processing-instruction production in lib/grammar.js lets the greedy S+ separator and lazy Char*? data group repeatedly repartition a long whitespace tail when the required closing ?> is absent. Both parsePI and parseProcessingInstruction apply the expression to the entire remaining source, causing quadratic backtracking during DOMParser.parseFromString() under default options and allowing a small unauthenticated XML input to stall the Node.js event loop. This issue is fixed in @⁠xmldom/xmldom version 0.9.11.

Publish Date: 2026-09-01

URL: CVE-2026-83606

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-g53g-w8rj-fmg7

Release Date: 2026-09-01

Fix Resolution (@⁠xmldom/xmldom): 0.9.11

Direct dependency fix Resolution (pdf2json): 3.1.6

In order to enable automatic remediation, please create workflow rules

CVE-2026-83605

Vulnerable Library - xmldom-0.9.7.tgz

A pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module.

Library home page: https://registry.npmjs.org/@⁠xmldom/xmldom/-/xmldom-0.9.7.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • pdf2json-3.1.5.tgz (Root Library)
    • ❌ xmldom-0.9.7.tgz (Vulnerable Library)

Found in base branch: dev

Vulnerability Details

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @⁠xmldom/xmldom versions 0.8.14 and 0.9.11, and in xmldom version 0.6.0 and earlier, Element.setAttribute() calls the private _createAttribute(name) path without validating the attribute name, while Document.createAttribute(name) validates against QName. XMLSerializer.serializeToString() emits attribute names verbatim, and requireWellFormed: true did not validate them, so a crafted name can terminate the intended attribute and inject additional attributes, including event handlers, into browser-consumed output; synthesized xmlns:PREFIX declarations expose the same unchecked-name boundary. This issue is fixed in @⁠xmldom/xmldom versions 0.8.14 and 0.9.11; no fixed version is available for xmldom.

Publish Date: 2026-09-01

URL: CVE-2026-83605

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-4w3w-2rp5-g8jm

Release Date: 2026-09-01

Fix Resolution (@⁠xmldom/xmldom): 0.9.11

Direct dependency fix Resolution (pdf2json): 3.1.6

In order to enable automatic remediation, please create workflow rules

CVE-2026-41675

Vulnerable Library - xmldom-0.9.7.tgz

A pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module.

Library home page: https://registry.npmjs.org/@⁠xmldom/xmldom/-/xmldom-0.9.7.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • pdf2json-3.1.5.tgz (Root Library)
    • ❌ xmldom-0.9.7.tgz (Vulnerable Library)

Found in base branch: dev

Vulnerability Details

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) "DOMParser" and "XMLSerializer" module. In @⁠xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, the package allows attacker-controlled processing instruction data to be serialized into XML without validating or neutralizing the PI-closing sequence ?>. As a result, an attacker can terminate the processing instruction early and inject arbitrary XML nodes into the serialized output. This issue has been patched in versions @⁠xmldom/xmldom versions 0.9.10 and 0.8.13.

Publish Date: 2026-05-07

URL: CVE-2026-41675

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-x6wf-f3px-wcqx

Release Date: 2026-04-22

Fix Resolution: @⁠xmldom/xmldom - 0.9.10

CVE-2026-41674

Vulnerable Library - xmldom-0.9.7.tgz

A pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module.

Library home page: https://registry.npmjs.org/@⁠xmldom/xmldom/-/xmldom-0.9.7.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • pdf2json-3.1.5.tgz (Root Library)
    • ❌ xmldom-0.9.7.tgz (Vulnerable Library)

Found in base branch: dev

Vulnerability Details

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) "DOMParser" and "XMLSerializer" module. In @⁠xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, the package serializes DocumentType node fields (internalSubset, publicId, systemId) verbatim without any escaping or validation. When these fields are set programmatically to attacker-controlled strings, XMLSerializer.serializeToString can produce output where the DOCTYPE declaration is terminated early and arbitrary markup appears outside it. This issue has been patched in versions @⁠xmldom/xmldom versions 0.9.10 and 0.8.13.

Publish Date: 2026-05-07

URL: CVE-2026-41674

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-f6ww-3ggp-fr8h

Release Date: 2026-04-22

Fix Resolution: @⁠xmldom/xmldom - 0.9.10

CVE-2026-41673

Vulnerable Library - xmldom-0.9.7.tgz

A pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module.

Library home page: https://registry.npmjs.org/@⁠xmldom/xmldom/-/xmldom-0.9.7.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • pdf2json-3.1.5.tgz (Root Library)
    • ❌ xmldom-0.9.7.tgz (Vulnerable Library)

Found in base branch: dev

Vulnerability Details

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) "DOMParser" and "XMLSerializer" module. In @⁠xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, seven recursive traversals in lib/dom.js operate without a depth limit. A sufficiently deeply nested DOM tree causes a RangeError: Maximum call stack size exceeded, crashing the application. This issue has been patched in versions @⁠xmldom/xmldom versions 0.9.10 and 0.8.13.

Publish Date: 2026-05-07

URL: CVE-2026-41673

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-2v35-w6hq-6mfw

Release Date: 2026-04-22

Fix Resolution: @⁠xmldom/xmldom - 0.9.10

CVE-2026-41672

Vulnerable Library - xmldom-0.9.7.tgz

A pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module.

Library home page: https://registry.npmjs.org/@⁠xmldom/xmldom/-/xmldom-0.9.7.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • pdf2json-3.1.5.tgz (Root Library)
    • ❌ xmldom-0.9.7.tgz (Vulnerable Library)

Found in base branch: dev

Vulnerability Details

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) "DOMParser" and "XMLSerializer" module. In @⁠xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, the package allows attacker-controlled comment content to be serialized into XML without validating or neutralizing comment-breaking sequences. As a result, an attacker can terminate the comment early and inject arbitrary XML nodes into the serialized output. This issue has been patched in versions @⁠xmldom/xmldom versions 0.9.10 and 0.8.13.

Publish Date: 2026-05-07

URL: CVE-2026-41672

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-j759-j44w-7fr8

Release Date: 2026-04-22

Fix Resolution: @⁠xmldom/xmldom - 0.9.10

CVE-2026-34601

Vulnerable Library - xmldom-0.9.7.tgz

A pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module.

Library home page: https://registry.npmjs.org/@⁠xmldom/xmldom/-/xmldom-0.9.7.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • pdf2json-3.1.5.tgz (Root Library)
    • ❌ xmldom-0.9.7.tgz (Vulnerable Library)

Found in base branch: dev

Vulnerability Details

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) "DOMParser" and "XMLSerializer" module. In xmldom versions 0.6.0 and prior and @⁠xmldom/xmldom prior to versions 0.8.12 and 0.9.9, xmldom/xmldom allows attacker-controlled strings containing the CDATA terminator ]]> to be inserted into a CDATASection node. During serialization, XMLSerializer emitted the CDATA content verbatim without rejecting or safely splitting the terminator. As a result, data intended to remain text-only became active XML markup in the serialized output, enabling XML structure injection and downstream business-logic manipulation. This issue has been patched in xmldom version 0.6.0 and @⁠xmldom/xmldom versions 0.8.12 and 0.9.9.

Publish Date: 2026-04-02

URL: CVE-2026-34601

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-wh4c-j3r5-mjhp

Release Date: 2026-04-01

Fix Resolution: @⁠xmldom/xmldom - 0.9.9

CVE-2026-83611

Vulnerable Library - xmldom-0.9.7.tgz

A pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module.

Library home page: https://registry.npmjs.org/@⁠xmldom/xmldom/-/xmldom-0.9.7.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • pdf2json-3.1.5.tgz (Root Library)
    • ❌ xmldom-0.9.7.tgz (Vulnerable Library)

Found in base branch: dev

Vulnerability Details

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @⁠xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, DOMParser.parseFromString() can silently accept an end tag such as </a\njunk>, close the element, and discard the trailing content. On 0.9.x, the lib/sax.js end-tag validator inherits the multiline flag from reg(), allowing the first line to satisfy the anchored XML ETag production; older lines have no equivalent residue validation. This parser differential can bypass a parse-before-trust well-formedness gate, although it does not inject the discarded content; onError on 0.9.x and errorHandler on 0.8.x are the relevant reporting interfaces. This issue is fixed in @⁠xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.

Publish Date: 2026-09-01

URL: CVE-2026-83611

CVSS 3 Score Details (5.3)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: Low
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-6h8r-xr42-gp59

Release Date: 2026-09-01

Fix Resolution (@⁠xmldom/xmldom): 0.9.12

Direct dependency fix Resolution (pdf2json): 3.1.6

In order to enable automatic remediation, please create workflow rules

CVE-2026-83610

Vulnerable Library - xmldom-0.9.7.tgz

A pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module.

Library home page: https://registry.npmjs.org/@⁠xmldom/xmldom/-/xmldom-0.9.7.tgz

Sample Path to Dependency File: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • pdf2json-3.1.5.tgz (Root Library)
    • ❌ xmldom-0.9.7.tgz (Vulnerable Library)

Found in base branch: dev

Vulnerability Details

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @⁠xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, Document.createEntityReference(name) accepts an invalid name and the ENTITY_REFERENCE_NODE serializer emits the resulting nodeName directly in &name; form. Directly serializing the node or fragment with XMLSerializer.serializeToString() and requireWellFormed: true can therefore break the entity-reference boundary and produce attacker-controlled XML markup when reparsed. The parser does not ordinarily create these nodes, and element-child insertion is rejected, so exploitation requires an application to create and directly serialize an EntityReference. This issue is fixed in @⁠xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.

Publish Date: 2026-09-01

URL: CVE-2026-83610

CVSS 3 Score Details (5.3)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: Low
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-6gmq-8vp8-gcm6

Release Date: 2026-09-01

Fix Resolution (@⁠xmldom/xmldom): 0.9.12

Direct dependency fix Resolution (pdf2json): 3.1.6

In order to enable automatic remediation, please create workflow rules


In order to enable automatic remediation for this issue, please create workflow rules

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions