CVE-2026-83606

high Red Hat
CVSS v3 Base Score
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Confidentiality
None
Integrity
None
Availability
High
Published: September 1, 2026 (5 days ago)
Last Modified: September 1, 2026
Vendor: Red Hat
Source: REDHAT

Description

A flaw was found in xmldom, a JavaScript XML DOM parser. This vulnerability, a Regular Expression Denial of Service (ReDoS), occurs due to inefficient processing of unterminated processing instructions in XML input. A remote, unauthenticated attacker can send a specially crafted XML input, causing quadratic backtracking and stalling the Node.js event loop. This can lead to a Denial of Service (DoS) for applications using xmldom.

CWE

CWE-1333

Affected Products

Red Hat OpenShift Container Platform 4

References