CVE-2026-83613

Source
https://cve.org/CVERecord?id=CVE-2026-83613
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-83613.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-83613
Aliases
  • GHSA-8344-3jmq-59r6
Downstream
Published
2026-09-01T14:38:49.617Z
Modified
2026-09-03T03:48:17.111071901Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
xmldom: Quadratic-time attribute deduplication
Details

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, DOMHandler.startElement in lib/dom-parser.js inserts every parsed attribute through setAttributeNode, while NamedNodeMap.setNamedItem in lib/dom.js calls the linear getNamedItem or getNamedItemNS lookup for each insertion. A well-formed element with many distinct attributes therefore requires quadratic comparisons during DOMParser.parseFromString() and can stall a Node.js event loop before application validation. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/83xxx/CVE-2026-83613.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-407"
    ]
}
References

Affected packages

Git / github.com/xmldom/xmldom

Affected ranges

Type
GIT
Repo
https://github.com/xmldom/xmldom
Events
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "0.6.0"
        },
        {
            "introduced": "0.9.0"
        },
        {
            "fixed": "0.9.12"
        },
        {
            "introduced": "0.7.0"
        },
        {
            "fixed": "0.8.15"
        }
    ]
}

Affected versions

0.*
0.7.0
0.7.0+scoped
0.7.0+unscoped
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.14
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.10
0.9.11
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
v0.*
v0.7.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-83613.json"