Vulnerabilities/

fast-xml-parser has stack overflow in XMLBuilder with preserveOrder

Severity:
Low

Description

Application crashes with stack overflow when user use XML builder with prserveOrder:true for following or similar input

Cause: arrToStr was not validating if the input is an array or a string and treating all non-array values as text content. What kind of vulnerability is it? Who is impacted?

Recommendation

Update the fast-xml-parser package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
fast-xml-parser
Anything's wrong? Let us know Last updated on March 06, 2026