THREAT OPS › Threat News › [GHSA] GHSA-93r5-fhx6-vmg9 (high) — xmldom: Quadratic-time parsing via the malformed-input recovery path — `parseElementStartPart` re-scan and `normalize()` adjacent-text merge
[GHSA] GHSA-93r5-fhx6-vmg9 (high) — xmldom: Quadratic-time parsing via the malformed-input recovery path — `parseElementStartPart` re-scan and `normalize()` adjacent-text merge
GHSA-93r5-fhx6-vmg9 Severity: high CVE: CVE-2026-83614
xmldom: Quadratic-time parsing via the malformed-input recovery path — `parseElementStartPart` re-scan and `normalize()` adjacent-text merge
## Summary
`xmldom`'s malformed-input **error-recovery path** has two quadratic-time (O(n²)) behaviors that a single crafted input triggers together, so a tiny, highly compressible document (tens of KB
Indicators of compromise
- bb7a085dc5ba1eea3212388509b97bb4b4af32b9sha1
- e5c14802592685bb872c042c54c3f73758875c85sha1
- CVE-2026-83614cve
Original source: https://github.com/advisories/GHSA-93r5-fhx6-vmg9