{"id":"GHSA-fj3w-jwp8-x2g3","summary":"fast-xml-parser has stack overflow in XMLBuilder with preserveOrder","details":"### Impact\nApplication crashes with stack overflow when user use XML builder with `prserveOrder:true` for following or similar input \n\n```\n[{\n    'foo': [\n        { 'bar': [{ '@_V': 'baz' }] }\n    ]\n}]\n```\n\nCause: `arrToStr` was not validating if the input is an array or a string and treating all non-array values as text content.\n_What kind of vulnerability is it? Who is impacted?_\n\n### Patches\nYes in 5.3.8\n\n### Workarounds\nUse XML builder with `preserveOrder:false` or check the input data before passing to builder.\n\n### References\n[_Are there any links users can visit to find out more?_](https://github.com/NaturalIntelligence/fast-xml-parser/pull/791)","aliases":["CVE-2026-27942"],"modified":"2026-07-17T21:12:33.179327491Z","published":"2026-02-26T22:33:10Z","database_specific":{"github_reviewed_at":"2026-02-26T22:33:10Z","nvd_published_at":"2026-02-26T02:16:22Z","cwe_ids":["CWE-120"],"severity":"LOW","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-fj3w-jwp8-x2g3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27942"},{"type":"WEB","url":"https://github.com/NaturalIntelligence/fast-xml-parser/pull/791"},{"type":"WEB","url":"https://github.com/NaturalIntelligence/fast-xml-parser/commit/c13a961910f14986295dd28484eee830fa1a0e8a"},{"type":"PACKAGE","url":"https://github.com/NaturalIntelligence/fast-xml-parser"}],"affected":[{"package":{"name":"fast-xml-parser","ecosystem":"npm","purl":"pkg:npm/fast-xml-parser"},"ranges":[{"type":"SEMVER","events":[{"introduced":"5.0.0"},{"fixed":"5.3.8"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-fj3w-jwp8-x2g3/GHSA-fj3w-jwp8-x2g3.json"}},{"package":{"name":"fast-xml-parser","ecosystem":"npm","purl":"pkg:npm/fast-xml-parser"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.0-beta.0"},{"fixed":"4.5.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-fj3w-jwp8-x2g3/GHSA-fj3w-jwp8-x2g3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U"}]}