CVE-2026-11169

ADVISORY - nist

Summary

Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted XML file. (Chromium security severity: Medium)

EPSS Score: 0.00029 (0.088)

Common Weakness Enumeration (CWE)

ADVISORY - nist

XML Injection (aka Blind XPath Injection)


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in