CVE-2026-41674: Red Hat Build Of Podman Desktop
High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, the package serializes DocumentType node fields (internalSubset, publicId, systemId) verbatim without any escaping or validation. When these fields are set programmatically to attacker-controlled strings, XMLSerializer.serializeToString can produce output where the DOCTYPE declaration is terminated early and arbitrary markup appears outside it. This issue has been patched in versions @xmldom/xmldom versions 0.9.10 and 0.8.13.
Affected products
- Red Hat Red Hat Build Of Podman Desktop
- Red Hat Red Hat Developer Hub 1.8: before 1779841586 (fixed in 1779841586)
- Red Hat Red Hat Developer Hub 1.9: before 1781187342 (fixed in 1781187342)
- Red Hat Red Hat Fuse 7
- Red Hat Red Hat Openshift Ai Rhoai
- Red Hat Red Hat Openshift Container Platform 4.20: before 1779864090 (fixed in 1779864090)
- Red Hat Red Hat Openshift Container Platform 4.21: before 1779252093 (fixed in 1779252093)
- Red Hat Self-Service Automation Portal 2
- Xmldom Xmldom
Published 2026-05-07. Last modified 2026-09-10.