CPE
medium
advisory
Unauthenticated Denial of Service in xmldom via Quadratic Complexity
1 CVEThe xmldom XML parser contains multiple O(n²) complexity flaws in its error-recovery path and DOM normalization logic, allowing an unauthenticated attacker to stall the Node.js event loop using crafted XML payloads.
xmldom +1
denial-of-service
vulnerability
web-application
1c
medium
advisory
Denial of Service via Quadratic Memory Consumption in xmldom
1 TTP 1 CVEThe xmldom parser suffers from a quadratic memory complexity flaw during namespace processing, allowing unauthenticated attackers to trigger process OOM crashes using small, crafted XML payloads.
xmldom +2
denial-of-service
vulnerability
xml
1t
1c