Denial of Service via Quadratic Memory Consumption in xmldom
The xmldom parser suffers from a quadratic memory complexity flaw during namespace processing, allowing unauthenticated attackers to trigger process OOM crashes using small, crafted XML payloads.
CVE search metadata
CVE search record: CVE-2026-83615. EPSS: 0.35%. KEV: no. Product: xmldom (>= 0.1.5, <= 0.6.0), @xmldom/xmldom (>= 0.7.0, <= 0.8.14), @xmldom/xmldom (>= 0.9.0, <= 0.9.11). Brief: Denial of Service via Quadratic Memory Consumption in xmldom. Brief link: https://feed.craftedsignal.io/briefs/2026-09-xmldom-memory-exhaustion/
The xmldom XML parser contains a vulnerability (CVE-2026-83615) stemming from inefficient namespace map handling during the parsing process. When the parser encounters an element that declares a namespace prefix, it performs a full copy of the current in-scope namespace map into a new object and retains this copy on the element while it remains open on the parse stack.
For deeply nested XML documents where each element declares a unique namespace, this mechanism leads to O(N²) memory consumption at the peak of the parse operation. Because this occurs during the initial parsing phase, it bypasses application-level security controls, such as schema validation or signature verification. An attacker can craft a small, highly compressible XML payload (less than 500 KB) that forces the parser to allocate gigabytes of heap memory, resulting in an unauthenticated denial-of-service (DoS) via OOM (Out-Of-Memory) process termination. This vulnerability affects multiple versions of both the legacy xmldom package and the current @xmldom/xmldom package.
Impact
Successful exploitation results in a full loss of service for any application utilizing vulnerable versions of xmldom to process attacker-influenced XML. Because the payload is small and highly compressible, it is effective against services that accept compressed XML over transports such as HTTP redirects or POST requests. The flaw is particularly critical for web services and middleware that parse untrusted XML before reaching authorization or authentication logic.
Recommendation
Prioritize patching all instances of xmldom and @xmldom/xmldom in your environment. Upgrade to versions that implement prototype-based namespace inheritance instead of full map cloning. Due to the nature of this memory exhaustion, traditional pattern-based WAF signatures may struggle to identify the payload; monitor process memory usage (RSS) on application servers for sudden spikes during XML parsing.
- Upgrade
@xmldom/xmldomto a version newer than 0.8.14 or 0.9.11. - Upgrade
xmldomto a version newer than 0.6.0. - Monitor application server logs for OOM crash events or unexpected restarts coinciding with high-frequency XML parsing.
- If immediate patching is not possible, implement input length and nesting depth validation before passing data to the DOMParser.
Immediate actions
Upgrade affected @xmldom/xmldom and xmldom packages to the latest patched versions.
Mitigations
Enforce strict XML depth limits in application-level input validation to mitigate the O(N^2) memory scaling.
CVE-2026-83615