← All CVEs NewScan detects
high

CVE-2026-83619

xmldom quadratic end-tag parsing denial of service

Severity
high
Affected product
@xmldom/xmldom
Affected versions
@xmldom/xmldom ≥ 0.7.0, < 0.8.15
Fixed in
@xmldom/xmldom 0.8.15
Added to NewScan
2026-09-02
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints @xmldom/xmldom from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-02 (/daily-cve). Version source is an exact @xmldom/xmldom pin from an anonymously served package.json, package-lock.json, or yarn.lock, already parsed by mine_versions; the scoped registry name is preserved, so this key joins directly. Versions 0.7.0 through 0.8.14 use a trailing-whitespace regex that takes quadratic time on a crafted end tag; 0.9.x uses a different parser and is outside this bounded row. Version-match only: NewScan never sends ReDoS payloads or concludes from timing, per the denial-of-service policy.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →