THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-x4fp-j954-r2f4 (high) — xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parser

[GHSA] GHSA-x4fp-j954-r2f4 (high) — xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parser

highgithub_advisoriesPublished 2026-09-08

GHSA-x4fp-j954-r2f4 Severity: high CVE: CVE-2026-83619

xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parser

## Summary

On the `@xmldom/xmldom` **`0.8.x`** line, parsing an XML end tag whose name is followed by a long run of whitespace and then a non-whitespace character triggers quadratic-time regular-expression backtracking (ReDoS), so a single small

Indicators of compromise

Original source: https://github.com/advisories/GHSA-x4fp-j954-r2f4