Input validation error in fast-xml-parser - CVE-2026-27942
Published: April 20, 2026
fast-xml-parser
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper input validation in arrToStr in XMLBuilder when processing input with preserveOrder enabled. A remote user can supply specially crafted input to cause a denial of service.
Only applications using the XML builder with preserveOrder set to true are vulnerable.