CVE-2026-27942
fast-xml-parser has stack overflow in XMLBuilder with preserveOrder
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. Prior to version 5.3.8, the application crashes with stack overflow when user use XML builder with `preserveOrder:true`. Version 5.3.8 fixes the issue. As a workaround, use XML builder with `preserveOrder:false` or check the input data before passing to builder.
| CWE | CWE-120 |
| Vendor | naturalintelligence |
| Product | fast-xml-parser |
| Published | Feb 26, 2026 |
| Last Updated | Feb 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for naturalintelligence fast-xml-parser
Be the first to know when new unknown vulnerabilities affecting naturalintelligence fast-xml-parser are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
NaturalIntelligence / fast-xml-parser
< 5.3.8