VDB
Sign up
LOW

GHSA-fj3w-jwp8-x2g3

fast-xml-parser has stack overflow in XMLBuilder with preserveOrder

Quick fix

GHSA-fj3w-jwp8-x2g3 — fast-xml-parser: upgrade to the fixed version with the command below.

npm install fast-xml-parser@5.3.8

Details

### Impact Application crashes with stack overflow when user use XML builder with `prserveOrder:true` for following or similar input

``` [{ 'foo': [ { 'bar': [{ '@_V': 'baz' }] } ] }] ```

Cause: `arrToStr` was not validating if the input is an array or a string and treating all non-array values as text content. _What kind of vulnerability is it? Who is impacted?_

### Patches Yes in 5.3.8

### Workarounds Use XML builder with `preserveOrder:false` or check the input data before passing to builder.

### References [_Are there any links users can visit to find out more?_](https://github.com/NaturalIntelligence/fast-xml-parser/pull/791)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/fast-xml-parser
Introduced in: 5.0.0Fixed in: 5.3.8
Fixnpm install fast-xml-parser@5.3.8
npm/fast-xml-parser
Introduced in: 4.0.0-beta.0Fixed in: 4.5.4
Fixnpm install fast-xml-parser@4.5.4

References