[Git][security-tracker-team/security-tracker][master] Add more node-xmldom issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Sep 1 21:42:17 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
0ebc0a81 by Salvatore Bonaccorso at 2026-09-01T22:40:32+02:00
Add more node-xmldom issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -160,25 +160,69 @@ CVE-2026-83615 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2
 	NOTE: Fixed by: https://github.com/xmldom/xmldom/commit/dabffe884e864eeecb1f515c716f875e1bc47ec1 (0.9.12)
 	NOTE: Fixed by: https://github.com/xmldom/xmldom/commit/954370f58c046223faf95ba77efcbc8ce014409d (0.8.15)
 CVE-2026-83614 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
-	TODO: check
+	- node-xmldom <unfixed>
+	NOTE: https://github.com/xmldom/xmldom/security/advisories/GHSA-93r5-fhx6-vmg9
+	NOTE: https://github.com/xmldom/xmldom/pull/1071
+	NOTE: https://github.com/xmldom/xmldom/pull/1072
+	NOTE: Fixed by: https://github.com/xmldom/xmldom/commit/0748720b620555f8c222782dcab575cf0cf403b4 (0.9.12)
+	NOTE: Fixed by: https://github.com/xmldom/xmldom/commit/f40ccb861eee0acbf5ee4feb9a34932e87b329c9 (0.8.15)
 CVE-2026-83613 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
-	TODO: check
+	- node-xmldom <unfixed>
+	NOTE: https://github.com/xmldom/xmldom/security/advisories/GHSA-8344-3jmq-59r6
+	NOTE: https://github.com/xmldom/xmldom/pull/1071
+	NOTE: https://github.com/xmldom/xmldom/pull/1072
+	NOTE: Fixed by: https://github.com/xmldom/xmldom/commit/cfb09b5dbeb035fdfedc9f01e2bbaf226bf47cf3 (0.9.12)
+	NOTE: Fixed by: https://github.com/xmldom/xmldom/commit/2c548f200cfec991cd5846627ef8f03542309213 (0.8.15)
 CVE-2026-83612 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
-	TODO: check
+	- node-xmldom <unfixed>
+	NOTE: https://github.com/xmldom/xmldom/security/advisories/GHSA-6mj3-qw4j-hgrw
+	NOTE: https://github.com/xmldom/xmldom/pull/1071
+	NOTE: Fixed by: https://github.com/xmldom/xmldom/commit/7ced40c06c28d151e996a97045018c3559ae4707 (0.9.12)
 CVE-2026-83611 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
-	TODO: check
+	- node-xmldom <unfixed>
+	NOTE: https://github.com/xmldom/xmldom/security/advisories/GHSA-6h8r-xr42-gp59
+	NOTE: https://github.com/xmldom/xmldom/pull/1071
+	NOTE: https://github.com/xmldom/xmldom/pull/1072
+	NOTE: Fixed by: https://github.com/xmldom/xmldom/commit/7b2ec67e1750daadd0bb06c92e875e726544a362 (0.9.12)
+	NOTE: Fixed by: https://github.com/xmldom/xmldom/commit/4430189660b0d380ee9c9ee7550a1358688e8828 (0.8.15)
 CVE-2026-83610 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
-	TODO: check
+	- node-xmldom <unfixed>
+	NOTE: https://github.com/xmldom/xmldom/security/advisories/GHSA-6gmq-8vp8-gcm6
+	NOTE: https://github.com/xmldom/xmldom/pull/1071
+	NOTE: https://github.com/xmldom/xmldom/pull/1072
+	NOTE: Fixed by: https://github.com/xmldom/xmldom/commit/4664386e4f4d99d17b416a151dbe8323e245284b (0.9.12)
+	NOTE: Fixed by: https://github.com/xmldom/xmldom/commit/6c3fb5ffeafe7901ec928ce9010988dd716c94a0 (0.8.15)
 CVE-2026-83609 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
-	TODO: check
+	- node-xmldom <unfixed>
+	NOTE: https://github.com/xmldom/xmldom/security/advisories/GHSA-3px3-54cx-rmw9
+	NOTE: https://github.com/xmldom/xmldom/pull/1071
+	NOTE: Fixed by: https://github.com/xmldom/xmldom/commit/7b2ec67e1750daadd0bb06c92e875e726544a362 (0.9.12)
 CVE-2026-83608 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
-	TODO: check
+	- node-xmldom <unfixed>
+	NOTE: https://github.com/xmldom/xmldom/security/advisories/GHSA-27p8-2357-5qqv
+	NOTE: https://github.com/xmldom/xmldom/pull/1071
+	NOTE: https://github.com/xmldom/xmldom/pull/1072
+	NOTE: Fixed by: https://github.com/xmldom/xmldom/commit/57aec90ac57b4408ae7c5d1746bf2a693b5ed90e (0.9.12)
+	NOTE: Fixed by: https://github.com/xmldom/xmldom/commit/85f12eb4d14b44de33216cfb72b50af4d24e9fdd (0.8.15)
 CVE-2026-83607 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
-	TODO: check
+	- node-xmldom 0.9.11-1
+	NOTE: https://github.com/xmldom/xmldom/security/advisories/GHSA-w2rr-34g9-rvrj
+	NOTE: https://github.com/xmldom/xmldom/pull/1043
+	NOTE: https://github.com/xmldom/xmldom/pull/1050
+	NOTE: Fixed by: https://github.com/xmldom/xmldom/commit/cba1321218b069182695813fa7565653708e172e (0.9.11)
+	NOTE: Fixed by: https://github.com/xmldom/xmldom/commit/d8212e632507eaf1d9f609657dd4c56abeb12d44 (0.8.14)
 CVE-2026-83606 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
-	TODO: check
+	- node-xmldom 0.9.11-1
+	NOTE: https://github.com/xmldom/xmldom/security/advisories/GHSA-g53g-w8rj-fmg7
+	NOTE: https://github.com/xmldom/xmldom/pull/1039
+	NOTE: Fixed by: https://github.com/xmldom/xmldom/commit/73df6b8bdbd86f904b9e8c3ab9c49aa54ef2802e (0.9.11)
 CVE-2026-83605 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
-	TODO: check
+	- node-xmldom 0.9.11-1
+	NOTE: https://github.com/xmldom/xmldom/security/advisories/GHSA-4w3w-2rp5-g8jm
+	NOTE: https://github.com/xmldom/xmldom/pull/1043
+	NOTE: https://github.com/xmldom/xmldom/pull/1050
+	NOTE: Fixed by: https://github.com/xmldom/xmldom/commit/cba1321218b069182695813fa7565653708e172e (0.9.11)
+	NOTE: Fixed by: https://github.com/xmldom/xmldom/commit/d8212e632507eaf1d9f609657dd4c56abeb12d44 (0.8.14)
 CVE-2026-83595 (AVideo contains a cross-site request forgery vulnerability in plugin/A ...)
 	TODO: check
 CVE-2026-83557 (DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator appli ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0ebc0a81ad3299bdb9d5849ac88ed3ccdfd5de74

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0ebc0a81ad3299bdb9d5849ac88ed3ccdfd5de74
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260901/84fab8bb/attachment.htm>


More information about the debian-security-tracker-commits mailing list