High severityGHSA Advisory· Published May 7, 2026· Updated May 7, 2026
CVE-2026-41673
CVE-2026-41673
Description
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, seven recursive traversals in lib/dom.js operate without a depth limit. A sufficiently deeply nested DOM tree causes a RangeError: Maximum call stack size exceeded, crashing the application. This issue has been patched in versions @xmldom/xmldom versions 0.9.10 and 0.8.13.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@xmldom/xmldomnpm | < 0.8.13 | 0.8.13 |
@xmldom/xmldomnpm | >= 0.9.0, < 0.9.10 | 0.9.10 |
xmldomnpm | <= 0.6.0 | — |
Affected products
12- osv-coords11 versionspkg:apk/chainguard/actions-runnerpkg:apk/chainguard/arangodb-3.11pkg:apk/chainguard/librechatpkg:apk/chainguard/npmpkg:apk/chainguard/safpkg:apk/chainguard/sqlpadpkg:apk/wolfi/npmpkg:apk/wolfi/safpkg:apk/wolfi/sqlpadpkg:npm/%40xmldom/xmldompkg:npm/xmldom
< 2.334.0-r1+ 10 more
- (no CPE)range: < 2.334.0-r1
- (no CPE)range: < 3.11.14.3-r6
- (no CPE)range: < 0.8.4-r6
- (no CPE)range: < 11.13.0-r1
- (no CPE)range: < 1.6.0-r0
- (no CPE)range: < 7.5.7-r18
- (no CPE)range: < 11.13.0-r1
- (no CPE)range: < 1.6.0-r0
- (no CPE)range: < 7.5.7-r18
- (no CPE)range: < 0.8.13
- (no CPE)range: <= 0.6.0
Patches
Vulnerability mechanics
References
14- github.com/advisories/GHSA-2v35-w6hq-6mfwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-41673ghsaADVISORY
- github.com/xmldom/xmldom/commit/17678a2a73ecbd1a2da90f3d47dc23da9cef81aanvdWEB
- github.com/xmldom/xmldom/commit/291257493cb0eb6980eda83b162a9c4e6d7d2597nvdWEB
- github.com/xmldom/xmldom/commit/2d6d6916ed8a4c223db1f6d7560ab4544c465b0fnvdWEB
- github.com/xmldom/xmldom/commit/430357c7b6333108856e917bf2367afe5ceb6f8anvdWEB
- github.com/xmldom/xmldom/commit/4845ef109221df0890825de2822fbe77afba3afenvdWEB
- github.com/xmldom/xmldom/commit/8834218c85ac2a4d757b9587c9028e67c2f7b6c3nvdWEB
- github.com/xmldom/xmldom/commit/8b7cfd1491314abdc347261921d7334ff15f7112nvdWEB
- github.com/xmldom/xmldom/commit/b0620383abc1df067f3ce1014c43ae1bc1161eebnvdWEB
- github.com/xmldom/xmldom/commit/e6edcab6bef5bcdba0b220bb35442aa72f452b84nvdWEB
- github.com/xmldom/xmldom/releases/tag/0.8.13nvdWEB
- github.com/xmldom/xmldom/releases/tag/0.9.10nvdWEB
- github.com/xmldom/xmldom/security/advisories/GHSA-2v35-w6hq-6mfwnvdWEB
News mentions
1- Patch Tuesday - May 2026Rapid7 Blog · May 13, 2026