Allocation of Resources Without Limits or Throttling in xmldom - CVE-2026-83615

 

Allocation of Resources Without Limits or Throttling in xmldom - CVE-2026-83615

Published: August 25, 2026 / Updated: September 2, 2026


Vulnerability identifier: #VU145137
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-83615
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in the XML parser namespace handling logic when parsing crafted XML documents with deeply nested elements that each declare a unique namespace prefix. A remote attacker can send a specially crafted XML document to cause a denial of service.

A small, highly compressible network-delivered payload can trigger quadratic peak memory consumption during parsing and crash the process before application-level validation runs.


Affected software

xmldom
IBM DataPower Gateway

How to mitigate CVE-2026-83615

Install security update from vendor's website.

xmldom - addressed in versions 0.8.15, 0.9.12
IBM DataPower Gateway - addressed in versions 10.5.0.23, 10.6.0.11, 11.0.0.3

External References

Related Security Bulletins