[security][CVE-2026-83614] @xmldom/xmldom in desktop packaging #177

Open
opened 2026-09-16 13:22:49 +00:00 by dirtydishes · 0 comments
Owner

Newly reported active High CVE from the 2026-09-16 scan. New means not previously reported by this automation; some disclosures predate this run. Correction: earlier scans incorrectly dropped Trivy status fixed, which means a patch is available, not installed.

CVE: CVE-2026-83614
Severity: High. CVSS: redhat: 7.5

Affected versions

  • @xmldom/xmldom@0.9.10 in bun.lock and deployment/docker/workspace-root/bun.lock

Project impact

apps/desktop -> Electron Forge -> @electron/packager@18.4.4 -> plist@3.1.1 -> @xmldom/xmldom@0.9.10. packager dist/mac.js loadPlist reads and parses plist files; plist lib/parse.js calls DOMParser.parseFromString(xml, "text/xml") before validating the root element. A malicious or compromised plist can stall or exhaust the desktop packaging process. Trusted inputs reduce exposure; no web/API XML endpoint was found.

Advisory description

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom versions 0.3.0 through 0.6.0, two independent quadratic paths can cause denial of service. In lib/sax.js, parseElementStartPart repeatedly rescans a malformed tag name to the next > during single-character recovery; in lib/dom.js, normalize() repeatedly removes and appends adjacent text nodes, causing quadratic reindexing and string rebuilding. The first path is reachable through default DOMParser.parseFromString() processing, while the second is also reachable through a direct normalize() call on a programmatically constructed DOM, and endDocument invokes that normalization after parsing. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.

Remediation

Resolve @xmldom/xmldom to 0.9.12 or later, which fixes this group of parser flaws. Update both Bun lockfiles through the existing workspace workflow and validate desktop packaging. Until patched, accept only trusted plist inputs and apply build time/memory limits.

Run counters, globally deduplicated by CVE ID

unaddressed critical CVEs: 6
unaddressed medium/low CVEs: 184
unaddressed total CVEs: 271

These are unresolved installed-version matches after explicit exclusions, not a claim that every inherited component is remotely exploitable. One UNKNOWN-severity record is retained separately and excluded from the requested severity total. Python requirements and apt-installed Python packages are unpinned, so their deployed versions cannot be established from this repository.

Resolution checks

Paginated all 171 Forgejo issue records and 101 PRs; checked local all-ref history. No matching CVE report or clear fixing change was found for this CVE. Its CVE registry state is PUBLISHED without a disputed tag. Existing reports for other flaws in the same component do not establish a fix for this one.

Sources

Newly reported active High CVE from the 2026-09-16 scan. New means not previously reported by this automation; some disclosures predate this run. Correction: earlier scans incorrectly dropped Trivy status `fixed`, which means a patch is available, not installed. CVE: CVE-2026-83614 Severity: High. CVSS: redhat: 7.5 Affected versions - @xmldom/xmldom@0.9.10 in bun.lock and deployment/docker/workspace-root/bun.lock Project impact apps/desktop -> Electron Forge -> @electron/packager@18.4.4 -> plist@3.1.1 -> @xmldom/xmldom@0.9.10. packager dist/mac.js loadPlist reads and parses plist files; plist lib/parse.js calls DOMParser.parseFromString(xml, "text/xml") before validating the root element. A malicious or compromised plist can stall or exhaust the desktop packaging process. Trusted inputs reduce exposure; no web/API XML endpoint was found. Advisory description xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom versions 0.3.0 through 0.6.0, two independent quadratic paths can cause denial of service. In lib/sax.js, parseElementStartPart repeatedly rescans a malformed tag name to the next > during single-character recovery; in lib/dom.js, normalize() repeatedly removes and appends adjacent text nodes, causing quadratic reindexing and string rebuilding. The first path is reachable through default DOMParser.parseFromString() processing, while the second is also reachable through a direct normalize() call on a programmatically constructed DOM, and endDocument invokes that normalization after parsing. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom. Remediation Resolve @xmldom/xmldom to 0.9.12 or later, which fixes this group of parser flaws. Update both Bun lockfiles through the existing workspace workflow and validate desktop packaging. Until patched, accept only trusted plist inputs and apply build time/memory limits. Run counters, globally deduplicated by CVE ID unaddressed critical CVEs: 6 unaddressed medium/low CVEs: 184 unaddressed total CVEs: 271 These are unresolved installed-version matches after explicit exclusions, not a claim that every inherited component is remotely exploitable. One UNKNOWN-severity record is retained separately and excluded from the requested severity total. Python requirements and apt-installed Python packages are unpinned, so their deployed versions cannot be established from this repository. Resolution checks Paginated all 171 Forgejo issue records and 101 PRs; checked local all-ref history. No matching CVE report or clear fixing change was found for this CVE. Its CVE registry state is PUBLISHED without a disputed tag. Existing reports for other flaws in the same component do not establish a fix for this one. Sources - https://www.cve.org/CVERecord?id=CVE-2026-83614 - https://nvd.nist.gov/vuln/detail/CVE-2026-83614 - https://github.com/xmldom/xmldom/security/advisories/GHSA-93r5-fhx6-vmg9
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dirtydishes/islandflow#177
No description provided.