CVE-2026-83619
xmldom quadratic end-tag parsing denial of service
- Severity
- high
- Affected product
- @xmldom/xmldom
- Affected versions
- @xmldom/xmldom ≥ 0.7.0, < 0.8.15
- Fixed in
- @xmldom/xmldom 0.8.15
- Added to NewScan
- 2026-09-02
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints @xmldom/xmldom from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-02 (/daily-cve). Version source is an exact @xmldom/xmldom pin from an anonymously served package.json, package-lock.json, or yarn.lock, already parsed by mine_versions; the scoped registry name is preserved, so this key joins directly. Versions 0.7.0 through 0.8.14 use a trailing-whitespace regex that takes quadratic time on a crafted end tag; 0.9.x uses a different parser and is outside this bounded row. Version-match only: NewScan never sends ReDoS payloads or concludes from timing, per the denial-of-service policy.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →