THREAT OPS › Threat News › [GHSA] GHSA-x4fp-j954-r2f4 (high) — xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parser
[GHSA] GHSA-x4fp-j954-r2f4 (high) — xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parser
GHSA-x4fp-j954-r2f4 Severity: high CVE: CVE-2026-83619
xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parser
## Summary
On the `@xmldom/xmldom` **`0.8.x`** line, parsing an XML end tag whose name is followed by a long run of whitespace and then a non-whitespace character triggers quadratic-time regular-expression backtracking (ReDoS), so a single small
Indicators of compromise
- e5c14802592685bb872c042c54c3f73758875c85sha1
- CVE-2026-83619cve
Original source: https://github.com/advisories/GHSA-x4fp-j954-r2f4