SB2026092932 - Multiple vulnerabilities in IBM DataPower Gateway
Published: September 29, 2026 Updated: September 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 8 vulnerabilities.
1) XML injection (CVE-ID: CVE-2026-83605)
CWE-ID: CWE-91 - XML Injection
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to inject attributes into serialized output.
The vulnerability exists due to improper input validation in Element.setAttribute() and XMLSerializer when processing user-controlled attribute names during serialization. A remote attacker can supply a crafted attribute name to inject attributes into serialized output.
This can include injection of event handler attributes into HTML output consumed by browsers, and the issue occurs because attribute names are emitted verbatim while only attribute values are escaped.
2) XML injection (CVE-ID: CVE-2026-83607)
CWE-ID: CWE-91 - XML Injection
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to inject arbitrary content into serialized XML or HTML output.
The vulnerability exists due to xml injection in Document.createElement() and XMLSerializer.serializeToString() when processing a user-controlled element name during serialization. A remote attacker can supply a specially crafted tagName value to inject arbitrary content into serialized XML or HTML output.
The issue bypasses the serializer's requireWellFormed check and can lead to cross-site scripting when the serialized output is consumed by a browser.
3) XML injection (CVE-ID: CVE-2026-83608)
CWE-ID: CWE-91 - XML Injection
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to inject arbitrary XML markup.
The vulnerability exists due to xml injection in the XML serializer DocumentType.name handling when serializing a document containing an attacker-controlled DocumentType name. A remote attacker can supply a crafted DocumentType name containing a doctype breakout sequence to inject arbitrary XML markup.
If the serialized output is processed as XHTML by a browser-based XML parser, injected script markup may execute. The issue bypasses the requireWellFormed check for DocumentType sibling fields because the name field is emitted verbatim.
4) Inefficient Algorithmic Complexity (CVE-ID: CVE-2026-83613)
CWE-ID: CWE-407 - Inefficient Algorithmic Complexity
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity in attribute deduplication in NamedNodeMap during XML parsing when processing a well-formed XML document containing a single element with many distinct attributes. A remote attacker can submit a specially crafted XML document to cause a denial of service.
The issue is triggered by valid input and does not require malformed markup, error recovery, namespace declarations, nesting, or non-default parser options.
5) Inefficient Algorithmic Complexity (CVE-ID: CVE-2026-83614)
CWE-ID: CWE-407 - Inefficient Algorithmic Complexity
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity in the DOMParser.parseFromString parsing path and normalize() when processing crafted malformed XML input or adjacent text nodes. A remote attacker can send a specially crafted XML document to cause a denial of service.
The parser path is reachable under default options from network-delivered XML, and the same quadratic behavior is also reachable through an explicit normalize() call on a programmatically built DOM containing adjacent text nodes.
6) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-83615)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the XML parser namespace handling logic when parsing crafted XML documents with deeply nested elements that each declare a unique namespace prefix. A remote attacker can send a specially crafted XML document to cause a denial of service.
A small, highly compressible network-delivered payload can trigger quadratic peak memory consumption during parsing and crash the process before application-level validation runs.
7) XML injection (CVE-ID: CVE-2026-83616)
CWE-ID: CWE-91 - XML Injection
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to inject arbitrary XML content into serialized output.
The vulnerability exists due to xml injection in Document.createProcessingInstruction() and the XML serializer when processing user-controlled processing-instruction target values during serialization. A remote attacker can supply a specially crafted target string to inject arbitrary XML content into serialized output.
If the serialized output is later processed as XHTML by a browser, injected script elements may execute. Exploitation requires application code to create processing instructions from untrusted target input and serialize the resulting document.
8) Inefficient regular expression complexity (CVE-ID: CVE-2026-83619)
CWE-ID: CWE-1333 - Inefficient Regular Expression Complexity
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient regular expression complexity in the end-tag parser in lib/sax.js when parsing an XML end tag whose name is followed by a long run of whitespace and then a non-whitespace character via DOMParser.parseFromString. A remote attacker can send a specially crafted XML document to cause a denial of service.
The issue is reachable under default options before any validity check and can stall the Node.js event loop during a single parse.
Remediation
Install update from vendor's website.