CVE-2026-27942Disclosure(naturalintelligence / fast-xml-parser)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. Prior to version 5.3.8, the application crashes with stack overflow when user use XML builder with `preserveOrder:true`. Version 5.3.8 fixes the issue. As a workaround, use XML builder with `preserveOrder:false` or check the input data before passing to builder.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-120

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fast-xml-parser

Threat summary

  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-02-26); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Products
fast-xml-parser

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-02-26: 2Mentions · 2026-02-27: 2Mentions · 2026-03-03: 1Mentions · 2026-03-15: 1Technical Details · 2026-02-26: 1Technical Details · 2026-02-27: 1Technical Details · 2026-03-03: 102-2602-2703-0303-15
Signal classification2 categories
Disclosure
466.7%
General
233.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-262
Disclosure1General1
2026-02-272
Disclosure2
2026-03-031
Disclosure1
2026-03-151
General1
Full discourse6 posts
  • CVE@CVEnew
    General

    CVE-2026-27942 fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. Prior to version 5.3.… https://www.cve.org/CVERecord?id=CVE-2026-27942

    Post summary

    The text merely references CVE-2026-27942 and links to its record, providing no substantive details on exploitation, patches, or technical aspects.

    00010108
    56.6K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    General

    🔍 Lambda Watchdog detected that CVE-2026-27942 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/430 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    The post informs that CVE‑2026‑27942 is no longer present in the latest AWS Lambda base images, based on Lambda Watchdog scans.

    0000035
    32 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-27942 (CVSS:2.7, HIGH) is Analyzed. fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based li..https://nvd.nist.gov/vuln/detail/CVE-2026-27942 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE-2026-27942, noting its CVSS score and that it involves the fast-xml-parser library, but provides no evidence of exploitation, patches, or PoC.

    0000021
    173 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New LOW CVE detected in AWS Lambda 🚨 CVE-2026-27942 impacts fast-xml-parser in 4 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/430 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    The post announces a new low‑severity CVE (CVE‑2026‑27942) affecting fast‑xml‑parser in several AWS Lambda base images, and provides links to a GitHub issue and a related security site for more details.

    0000033
    30 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27942: Infinite Loops & Broken Dreams: The fast-xml-parser Stack Exhaustion In the world of JavaScript, trusting your input types is a rookie mistake that even seasoned developers make. CVE-2026-27942 is a classic example of this hubris: a De... https://cvereports.com/reports/CVE-2026-27942

    Post summary

    The post announces a stack exhaustion vulnerability in fast‑xml‑parser (CVE-2026-27942) but does not provide PoC, exploit code, or patch information.

    0000040
    32 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27942 Stack Overflow Vulnerability in Fast-XML-Parser Before Version 5.3.8 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27942

    Post summary

    A stack overflow vulnerability in Fast‑XML‑Parser before version 5.3.8 (CVE-2026-27942) is disclosed, with no PoC, exploit, or patch details provided.

    0000034
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnaturalintelligencefast-xml-parser---

Explore more