wid-sec-w-2026-1039
·
Published 2026-04-09
·
View on BSI CERT-Bund ↗
IBM DataPower Gateway: Vulnerability allows Denial of Service
CVSS N/A
NONE
Risk Summary
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 5.0.9 through 5.3.3, a RangeError vulnerability exists in the numeric entity processing of fast-xml-parser when parsing XML with out-of-range entity code points (e.g., `�` or `�`). This causes the parser to throw an uncaught exception, crashing any application that processes untrusted XML input. Version 5.3.4 fixes the issue.
CVEs (1)
Affected Vendors
IBM
Affected Products (6)
IBM
·
DataPower Gateway
<11.0.0.0
IBM
·
DataPower Gateway
11.0.0.0
IBM
·
DataPower Gateway
<10.6.0.9
IBM
·
DataPower Gateway
10.6.0.9
IBM
·
DataPower Gateway
<10.5.0.21
IBM
·
DataPower Gateway
10.5.0.21
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more