Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-27942

Опубликовано: 26 фев. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. Prior to version 5.3.8, the application crashes with stack overflow when user use XML builder with preserveOrder:true. Version 5.3.8 fixes the issue. As a workaround, use XML builder with preserveOrder:false or check the input data before passing to builder.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:naturalintelligence:fast-xml-parser:*:*:*:*:*:*:*:*
Версия до 4.5.4 (исключая)
cpe:2.3:a:naturalintelligence:fast-xml-parser:*:*:*:*:*:*:*:*
Версия от 5.0.0 (включая) до 5.3.8 (исключая)

EPSS

Процентиль: 15%
0.0005
Низкий

7.5 High

CVSS3

Дефекты

CWE-120

Связанные уязвимости

CVSS3: 7.5
ubuntu
30 дней назад

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. Prior to version 5.3.8, the application crashes with stack overflow when user use XML builder with `preserveOrder:true`. Version 5.3.8 fixes the issue. As a workaround, use XML builder with `preserveOrder:false` or check the input data before passing to builder.

CVSS3: 7.5
redhat
30 дней назад

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. Prior to version 5.3.8, the application crashes with stack overflow when user use XML builder with `preserveOrder:true`. Version 5.3.8 fixes the issue. As a workaround, use XML builder with `preserveOrder:false` or check the input data before passing to builder.

CVSS3: 7.5
debian
30 дней назад

fast-xml-parser allows users to validate XML, parse XML to JS object, ...

github
29 дней назад

fast-xml-parser has stack overflow in XMLBuilder with preserveOrder

EPSS

Процентиль: 15%
0.0005
Низкий

7.5 High

CVSS3

Дефекты

CWE-120