CVE-2026-83614: xmldom: Quadratic-time parsing via the malformed-input recovery path — `parseElementStartPart` re-scan and `normalize()` adjacent-text merge
Overview
- Severity
- N/A
- Exploit Status
- Not Exploited
- Patch Tuesday
- 2026-Sep
- Released
- 2026-09-06
- EPSS Score
- 0.35% (percentile: 28.1%)
Affected Products (1)
Other
Security Updates (1)
Revision History
- 2026-09-06: Information published.