[security][CVE-2026-83606] @xmldom/xmldom in desktop packaging #175

Open
opened 2026-09-16 13:22:48 +00:00 by dirtydishes · 0 comments
Owner

Newly reported active High CVE from the 2026-09-16 scan. New means not previously reported by this automation; some disclosures predate this run. Correction: earlier scans incorrectly dropped Trivy status fixed, which means a patch is available, not installed.

CVE: CVE-2026-83606
Severity: High. CVSS: redhat: 7.5

Affected versions

  • @xmldom/xmldom@0.9.10 in bun.lock and deployment/docker/workspace-root/bun.lock

Project impact

apps/desktop -> Electron Forge -> @electron/packager@18.4.4 -> plist@3.1.1 -> @xmldom/xmldom@0.9.10. packager dist/mac.js loadPlist reads and parses plist files; plist lib/parse.js calls DOMParser.parseFromString(xml, "text/xml") before validating the root element. A malicious or compromised plist can stall or exhaust the desktop packaging process. Trusted inputs reduce exposure; no web/API XML endpoint was found.

Advisory description

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0-beta.9 until 0.9.11, the processing-instruction production in lib/grammar.js lets the greedy S+ separator and lazy Char*? data group repeatedly repartition a long whitespace tail when the required closing ?> is absent. Both parsePI and parseProcessingInstruction apply the expression to the entire remaining source, causing quadratic backtracking during DOMParser.parseFromString() under default options and allowing a small unauthenticated XML input to stall the Node.js event loop. This issue is fixed in @xmldom/xmldom version 0.9.11.

Remediation

Resolve @xmldom/xmldom to 0.9.12 or later, which fixes this group of parser flaws. Update both Bun lockfiles through the existing workspace workflow and validate desktop packaging. Until patched, accept only trusted plist inputs and apply build time/memory limits.

Run counters, globally deduplicated by CVE ID

unaddressed critical CVEs: 6
unaddressed medium/low CVEs: 184
unaddressed total CVEs: 271

These are unresolved installed-version matches after explicit exclusions, not a claim that every inherited component is remotely exploitable. One UNKNOWN-severity record is retained separately and excluded from the requested severity total. Python requirements and apt-installed Python packages are unpinned, so their deployed versions cannot be established from this repository.

Resolution checks

Paginated all 171 Forgejo issue records and 101 PRs; checked local all-ref history. No matching CVE report or clear fixing change was found for this CVE. Its CVE registry state is PUBLISHED without a disputed tag. Existing reports for other flaws in the same component do not establish a fix for this one.

Sources

Newly reported active High CVE from the 2026-09-16 scan. New means not previously reported by this automation; some disclosures predate this run. Correction: earlier scans incorrectly dropped Trivy status `fixed`, which means a patch is available, not installed. CVE: CVE-2026-83606 Severity: High. CVSS: redhat: 7.5 Affected versions - @xmldom/xmldom@0.9.10 in bun.lock and deployment/docker/workspace-root/bun.lock Project impact apps/desktop -> Electron Forge -> @electron/packager@18.4.4 -> plist@3.1.1 -> @xmldom/xmldom@0.9.10. packager dist/mac.js loadPlist reads and parses plist files; plist lib/parse.js calls DOMParser.parseFromString(xml, "text/xml") before validating the root element. A malicious or compromised plist can stall or exhaust the desktop packaging process. Trusted inputs reduce exposure; no web/API XML endpoint was found. Advisory description xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0-beta.9 until 0.9.11, the processing-instruction production in lib/grammar.js lets the greedy S+ separator and lazy Char*? data group repeatedly repartition a long whitespace tail when the required closing ?> is absent. Both parsePI and parseProcessingInstruction apply the expression to the entire remaining source, causing quadratic backtracking during DOMParser.parseFromString() under default options and allowing a small unauthenticated XML input to stall the Node.js event loop. This issue is fixed in @xmldom/xmldom version 0.9.11. Remediation Resolve @xmldom/xmldom to 0.9.12 or later, which fixes this group of parser flaws. Update both Bun lockfiles through the existing workspace workflow and validate desktop packaging. Until patched, accept only trusted plist inputs and apply build time/memory limits. Run counters, globally deduplicated by CVE ID unaddressed critical CVEs: 6 unaddressed medium/low CVEs: 184 unaddressed total CVEs: 271 These are unresolved installed-version matches after explicit exclusions, not a claim that every inherited component is remotely exploitable. One UNKNOWN-severity record is retained separately and excluded from the requested severity total. Python requirements and apt-installed Python packages are unpinned, so their deployed versions cannot be established from this repository. Resolution checks Paginated all 171 Forgejo issue records and 101 PRs; checked local all-ref history. No matching CVE report or clear fixing change was found for this CVE. Its CVE registry state is PUBLISHED without a disputed tag. Existing reports for other flaws in the same component do not establish a fix for this one. Sources - https://www.cve.org/CVERecord?id=CVE-2026-83606 - https://nvd.nist.gov/vuln/detail/CVE-2026-83606 - https://github.com/xmldom/xmldom/security/advisories/GHSA-g53g-w8rj-fmg7
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dirtydishes/islandflow#175
No description provided.