๐Ÿ” CVE Alert

CVE-2026-83613

UNKNOWN 0.0

xmldom: Quadratic-time attribute deduplication

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, DOMHandler.startElement in lib/dom-parser.js inserts every parsed attribute through setAttributeNode, while NamedNodeMap.setNamedItem in lib/dom.js calls the linear getNamedItem or getNamedItemNS lookup for each insertion. A well-formed element with many distinct attributes therefore requires quadratic comparisons during DOMParser.parseFromString() and can stall a Node.js event loop before application validation. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.

CWE CWE-407
Vendor xmldom
Product xmldom
Published Sep 1, 2026
Stay Ahead of the Next One

Get instant alerts for xmldom xmldom

Be the first to know when new unknown vulnerabilities affecting xmldom xmldom are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

xmldom / xmldom
<= 0.6.0
@xmldom / xmldom
>= 0.9.0, < 0.9.12 >= 0.7.0, < 0.8.15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/xmldom/xmldom/security/advisories/GHSA-8344-3jmq-59r6 github.com: https://github.com/xmldom/xmldom/pull/1071 github.com: https://github.com/xmldom/xmldom/pull/1072 github.com: https://github.com/xmldom/xmldom/commit/2c548f200cfec991cd5846627ef8f03542309213 github.com: https://github.com/xmldom/xmldom/commit/cfb09b5dbeb035fdfedc9f01e2bbaf226bf47cf3 github.com: https://github.com/xmldom/xmldom/releases/tag/0.8.15 github.com: https://github.com/xmldom/xmldom/releases/tag/0.9.12