THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-965w-775f-mr7g (high) — xmldom: Quadratic-memory consumption

[GHSA] GHSA-965w-775f-mr7g (high) — xmldom: Quadratic-memory consumption

highgithub_advisoriesPublished 2026-09-08

GHSA-965w-775f-mr7g Severity: high CVE: CVE-2026-83615

xmldom: Quadratic-memory consumption

## Summary

When an element declares a namespace prefix, xmldom copies the entire in-scope namespace map into a fresh object and keeps that copy on the element while it is open on the parse stack. A crafted document that nests N elements, each declaring one unique prefix, therefore drives the parser to ho

Indicators of compromise

Original source: https://github.com/advisories/GHSA-965w-775f-mr7g