Vulnerabilities/

xmldom: Uncontrolled recursion in XML serialization leads to DoS - xmldom

Severity:
High

Description

Seven recursive traversals in lib/dom.js operate without a depth limit. A sufficiently deeply nested DOM tree causes a RangeError: Maximum call stack size exceeded, crashing the application.

Reported operations:

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
xmldom
Anything's wrong? Let us know Last updated on May 08, 2026