Skip to content

chore(deps): update dependency fast-xml-parser to v5.3.8 [security]#705

Merged
leomp12 merged 1 commit intomainfrom
renovate/npm-fast-xml-parser-vulnerability
Mar 2, 2026
Merged

chore(deps): update dependency fast-xml-parser to v5.3.8 [security]#705
leomp12 merged 1 commit intomainfrom
renovate/npm-fast-xml-parser-vulnerability

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Feb 28, 2026

This PR contains the following updates:

Package Change Age Confidence
fast-xml-parser 5.3.75.3.8 age confidence

GitHub Vulnerability Alerts

CVE-2026-27942

Impact

Application crashes with stack overflow when user use XML builder with prserveOrder:true for following or similar input:

[{
    'foo': [
        { 'bar': [{ '@​_V': 'baz' }] }
    ]
}]

Cause: arrToStr was not validating if the input is an array or a string and treating all non-array values as text content.
What kind of vulnerability is it? Who is impacted?

Patches

Yes, in 5.3.8 and 4.5.4.

Workarounds

Use XML builder with preserveOrder:false or check the input data before passing to builder.


Release Notes

NaturalIntelligence/fast-xml-parser (fast-xml-parser)

v5.3.8: handle non-array input for XML builder && support maxNestedTags

Compare Source


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the dependencies Pull requests that update a dependency file label Feb 28, 2026
@renovate renovate bot force-pushed the renovate/npm-fast-xml-parser-vulnerability branch from 452f15f to 68393f2 Compare March 2, 2026 13:33
@renovate renovate bot changed the title chore(deps): update dependency fast-xml-parser to v5.3.8 [security] chore(deps): update dependency fast-xml-parser to v5.3.8 [security] - autoclosed Mar 2, 2026
@renovate renovate bot closed this Mar 2, 2026
@renovate renovate bot deleted the renovate/npm-fast-xml-parser-vulnerability branch March 2, 2026 15:25
@renovate renovate bot changed the title chore(deps): update dependency fast-xml-parser to v5.3.8 [security] - autoclosed chore(deps): update dependency fast-xml-parser to v5.3.8 [security] Mar 2, 2026
@renovate renovate bot reopened this Mar 2, 2026
@renovate renovate bot force-pushed the renovate/npm-fast-xml-parser-vulnerability branch 2 times, most recently from 68393f2 to e439517 Compare March 2, 2026 16:51
@leomp12 leomp12 merged commit f805101 into main Mar 2, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant