Allocation of Resources Without Limits or Throttling in xmldom - CVE-2026-83615
Published: August 25, 2026 / Updated: September 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the XML parser namespace handling logic when parsing crafted XML documents with deeply nested elements that each declare a unique namespace prefix. A remote attacker can send a specially crafted XML document to cause a denial of service.
A small, highly compressible network-delivered payload can trigger quadratic peak memory consumption during parsing and crash the process before application-level validation runs.
Affected software
IBM DataPower Gateway
How to mitigate CVE-2026-83615
IBM DataPower Gateway - addressed in versions 10.5.0.23, 10.6.0.11, 11.0.0.3