Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-27942

Опубликовано: 26 фев. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. Prior to version 5.3.8, the application crashes with stack overflow when user use XML builder with preserveOrder:true. Version 5.3.8 fixes the issue. As a workaround, use XML builder with preserveOrder:false or check the input data before passing to builder.

A flaw was found in fast-xml-parser. A user can exploit this flaw by processing specially crafted XML data with the XML builder when the preserveOrder option is enabled. This can lead to a stack overflow, causing the application to crash and resulting in a Denial of Service (DoS).

Меры по смягчению последствий

To mitigate this vulnerability, configure applications using the fast-xml-parser XML builder to set the preserveOrder option to false. Alternatively, ensure that all XML input data is thoroughly validated before being passed to the builder to prevent the processing of malicious or malformed content.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Applications 8mta/mta-ui-rhel9Affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-main-rhel8Affected
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Affected
Red Hat Openshift Data Foundation 4odf4/mcg-core-rhel9Affected
Red Hat Openshift Data Foundation 4odf4/ocs-client-console-rhel9Affected
Red Hat Openshift Data Foundation 4odf4/odf-console-rhel9Affected
Red Hat Openshift Data Foundation 4odf4/odf-multicluster-console-rhel9Not affected
Red Hat OpenShift GitOpsopenshift-gitops-1/argocd-rhel8Affected
Red Hat OpenShift GitOpsopenshift-gitops-1/argocd-rhel9Affected
Red Hat OpenShift Virtualization 4container-native-virtualization/kubevirt-console-pluginAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-776
https://bugzilla.redhat.com/show_bug.cgi?id=2442938fast-xml-parser: fast-xml-parser: Stack overflow leads to Denial of Service

EPSS

Процентиль: 15%
0.0005
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
30 дней назад

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. Prior to version 5.3.8, the application crashes with stack overflow when user use XML builder with `preserveOrder:true`. Version 5.3.8 fixes the issue. As a workaround, use XML builder with `preserveOrder:false` or check the input data before passing to builder.

CVSS3: 7.5
nvd
30 дней назад

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. Prior to version 5.3.8, the application crashes with stack overflow when user use XML builder with `preserveOrder:true`. Version 5.3.8 fixes the issue. As a workaround, use XML builder with `preserveOrder:false` or check the input data before passing to builder.

CVSS3: 7.5
debian
30 дней назад

fast-xml-parser allows users to validate XML, parse XML to JS object, ...

github
29 дней назад

fast-xml-parser has stack overflow in XMLBuilder with preserveOrder

EPSS

Процентиль: 15%
0.0005
Низкий

7.5 High

CVSS3