๐Ÿ” CVE Alert

CVE-2026-83615

UNKNOWN 0.0

xmldom: Quadratic-memory consumption

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom versions 0.1.5 through 0.6.0, appendElement in lib/sax.js uses _copy to clone the complete currentNSMap for each nested element that declares a new namespace prefix. Keeping every ancestor map live on the parse stack creates quadratic peak namespace-map storage, so a small highly compressible XML document can exhaust the process heap before application validation. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.

CWE CWE-770
Vendor xmldom
Product xmldom
Published Sep 1, 2026
Stay Ahead of the Next One

Get instant alerts for xmldom xmldom

Be the first to know when new unknown vulnerabilities affecting xmldom xmldom are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

xmldom / xmldom
>= 0.1.5, <= 0.6.0
@xmldom / xmldom
>= 0.7.0, < 0.8.15 >= 0.9.0, < 0.9.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/xmldom/xmldom/security/advisories/GHSA-965w-775f-mr7g github.com: https://github.com/xmldom/xmldom/pull/1071 github.com: https://github.com/xmldom/xmldom/pull/1072 github.com: https://github.com/xmldom/xmldom/commit/954370f58c046223faf95ba77efcbc8ce014409d github.com: https://github.com/xmldom/xmldom/commit/dabffe884e864eeecb1f515c716f875e1bc47ec1 github.com: https://github.com/xmldom/xmldom/releases/tag/0.8.15 github.com: https://github.com/xmldom/xmldom/releases/tag/0.9.12