<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>@Xmldom/Xmldom (0.7.0 &lt;= 0.8.14, 0.9.0 &lt;= 0.9.11) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/@xmldom/xmldom-0.7.0--0.8.14-0.9.0--0.9.11/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 08 Sep 2026 21:53:02 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/@xmldom/xmldom-0.7.0--0.8.14-0.9.0--0.9.11/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Denial of Service in xmldom via Quadratic Complexity</title><link>https://feed.craftedsignal.io/briefs/2026-09-xmldom-dos/</link><pubDate>Tue, 08 Sep 2026 21:53:02 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-xmldom-dos/</guid><description>The xmldom XML parser contains multiple O(n²) complexity flaws in its error-recovery path and DOM normalization logic, allowing an unauthenticated attacker to stall the Node.js event loop using crafted XML payloads.</description><content:encoded><![CDATA[<p>The <code>xmldom</code> library, commonly used for XML parsing in Node.js environments, is vulnerable to a denial of service (DoS) attack due to two distinct quadratic-time (O(n²)) complexity vulnerabilities. An attacker can supply a small, highly compressible XML document that exploits the parser's error-recovery path, leading to prolonged CPU exhaustion and event loop starvation.</p>
<p>The first vulnerability occurs during the <code>parseElementStartPart</code> process, where the parser's error-recovery mechanism performs redundant character scanning when encountering specific malformed XML inputs. The second vulnerability exists within the <code>DOM.normalize()</code> method, which inefficiently merges adjacent text nodes created during the parsing recovery process. These issues are reachable through the default <code>DOMParser.parseFromString</code> method, and the <code>normalize()</code> flaw is also independently accessible via the public DOM API if an application builds a tree from untrusted input. These vulnerabilities affect the entire history of the project, including current 0.8.x and 0.9.x branches.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in a persistent hang of the single-threaded Node.js event loop, preventing the application from processing any concurrent requests. Because the vulnerabilities are triggered by the default XML parser configuration and require no authentication, they represent a high risk to any service that accepts XML input from external sources. The attack is highly efficient, as payloads as small as 32 KB can cause multi-second stalls, which scale quadratically as document size increases.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for development and security teams:</p>
<ul>
<li>Update all dependencies using <code>xmldom</code> or <code>@xmldom/xmldom</code> to the patched versions immediately to remediate CVE-2026-83614.</li>
<li>Implement strict input size limits for any endpoint accepting XML payloads to mitigate the impact of quadratic complexity attacks.</li>
<li>Audit custom code that programmatically builds DOM trees using untrusted input, ensuring that <code>normalize()</code> is not called on unvalidated or deeply nested structures.</li>
<li>Configure <code>DOMParser</code> with custom error handlers to identify and reject malformed input early, rather than relying on the default error-recovery path.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>denial-of-service</category><category>vulnerability</category><category>web-application</category></item></channel></rss>