Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-41673

32
FAUCET Score

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, seven recursive traversals in lib/dom.js operate without a depth limit. A sufficiently deeply nested DOM tree causes a RangeError: Maximum call stack size exceeded, crashing the application. This issue has been patched in versions @xmldom/xmldom versions 0.9.10 and 0.8.13.

First published: May 7, 2026Last modified: May 7, 2026

Impacted Technologies

VendorProductVersion(s)CPE
XmldomXmldom
@xmldom/xmldom < 0.8.13, @xmldom/xmldom >= 0.9.0, < 0.9.10, xmldom <= 0.6.0CNA affected

CVSS Data

CVSS version used by this source: 4.0

8.7HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.64%
Probability of exploitation in next 30 days
EPSS Percentile
47.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0064 is in the 23rd percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

npmpatch availablevia ghsa
Product: @xmldom/xmldomFixed in: 0.8.13
npmpatch availablevia ghsa
Product: @xmldom/xmldomFixed in: 0.9.10

Vendor Advisories (2)

microsoft2026-May/CVE-2026-41673Important

xmldom: Denial of service via uncontrolled recursion in XML serialization

May 7, 2026
npmGHSA-2v35-w6hq-6mfwhigh

xmldom: Uncontrolled recursion in XML serialization leads to DoS

Apr 22, 2026

References

access.redhat.com / errata/RHSA-2026:26234
access.redhat.com / security/cve/CVE-2026-41673
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-41673.json
github.com / xmldom/xmldom/commit/17678a2a73ecbd1a2da90f3d47dc23da9cef81aa
github.com / xmldom/xmldom/commit/291257493cb0eb6980eda83b162a9c4e6d7d2597
github.com / xmldom/xmldom/commit/2d6d6916ed8a4c223db1f6d7560ab4544c465b0f
github.com / xmldom/xmldom/commit/430357c7b6333108856e917bf2367afe5ceb6f8a
github.com / xmldom/xmldom/commit/4845ef109221df0890825de2822fbe77afba3afe
github.com / xmldom/xmldom/commit/8834218c85ac2a4d757b9587c9028e67c2f7b6c3
github.com / xmldom/xmldom/commit/8b7cfd1491314abdc347261921d7334ff15f7112
github.com / xmldom/xmldom/commit/b0620383abc1df067f3ce1014c43ae1bc1161eeb
github.com / xmldom/xmldom/commit/e6edcab6bef5bcdba0b220bb35442aa72f452b84
github.com / xmldom/xmldom/releases/tag/0.8.13
github.com / xmldom/xmldom/releases/tag/0.9.10
github.com / xmldom/xmldom/security/advisories/GHSA-2v35-w6hq-6mfw