CVE-2026-41673: high-severity vulnerability in xmldom
xmldom: Denial of service via uncontrolled recursion in XML serialization
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
The xmldom library crashes when processing XML documents with very deeply nested elements due to unlimited recursion during serialization. An attacker can send a specially crafted XML file to crash applications using vulnerable versions of this library.
Uncontrolled recursion in seven XML serialization traversal functions in lib/dom.js lacks depth limiting, allowing a deeply nested DOM tree to trigger stack exhaustion (RangeError). Attack vector is remote via malicious XML input; no authentication required. Impact is denial of service through application crash.
In the same product, most dangerous first.