Inefficient Algorithmic Complexity in xmldom - CVE-2026-83614
Published: August 25, 2026 / Updated: September 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity in the DOMParser.parseFromString parsing path and normalize() when processing crafted malformed XML input or adjacent text nodes. A remote attacker can send a specially crafted XML document to cause a denial of service.
The parser path is reachable under default options from network-delivered XML, and the same quadratic behavior is also reachable through an explicit normalize() call on a programmatically built DOM containing adjacent text nodes.
Affected software
IBM DataPower Gateway
How to mitigate CVE-2026-83614
IBM DataPower Gateway - addressed in versions 10.5.0.23, 10.6.0.11, 11.0.0.3