← Back to home
wid-sec-w-2026-1039  ·  Published 2026-04-09  ·  View on BSI CERT-Bund ↗

IBM DataPower Gateway: Vulnerability allows Denial of Service

CVSS N/A NONE

Risk Summary

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 5.0.9 through 5.3.3, a RangeError vulnerability exists in the numeric entity processing of fast-xml-parser when parsing XML with out-of-range entity code points (e.g., `�` or `�`). This causes the parser to throw an uncaught exception, crashing any application that processes untrusted XML input. Version 5.3.4 fixes the issue.

CVEs (1)

Affected Vendors

IBM

Affected Products (6)

IBM · DataPower Gateway <11.0.0.0
IBM · DataPower Gateway 11.0.0.0
IBM · DataPower Gateway <10.6.0.9
IBM · DataPower Gateway 10.6.0.9
IBM · DataPower Gateway <10.5.0.21
IBM · DataPower Gateway 10.5.0.21

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more