Vulnerabilities/

xmldom: Uncontrolled recursion in XML serialization leads to DoS

Severity:
High

Description

Seven recursive traversals in lib/dom.js operate without a depth limit. A sufficiently deeply nested DOM tree causes a RangeError: Maximum call stack size exceeded, crashing the application.

Reported operations:

Recommendation

Update the @xmldom/xmldom package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@xmldom/xmldom
Anything's wrong? Let us know Last updated on May 08, 2026