PatchSiren cyber security CVE debrief
CVE-2026-41673 xmldom CVE debrief
CVE-2026-41673 is a high-severity vulnerability in xmldom, a JavaScript XML DOM module. Versions prior to 0.9.10 and 0.8.13 are affected, allowing for a RangeError: Maximum call stack size exceeded due to seven recursive traversals in lib/dom.js operating without a depth limit. A sufficiently deeply nested DOM tree causes the application to crash. This issue has been patched in versions @xmldom/xmldom versions 0.9.10 and 0.8.13. The vulnerability has a CVSS score of 8.7 and is considered HIGH severity. The CVE was published on 2026-05-07T04:16:33.257Z and last modified on 2026-07-01T13:17:14.150Z.
- Vendor
- xmldom
- Product
- Unknown
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-07
- Original CVE updated
- 2026-08-28
- Advisory published
- 2026-05-07
- Advisory updated
- 2026-08-28
Who should care
Developers and administrators using xmldom versions prior to 0.9.10 and 0.8.13 should be aware of this vulnerability. The issue can cause applications to crash, leading to denial-of-service (DoS) attacks. Users of Red Hat products may also be affected, as indicated by Red Hat's security advisories.
Technical summary
The xmldom module, a pure JavaScript implementation of the W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer`, has a vulnerability in versions prior to 0.9.10 and 0.8.13. The issue arises from seven recursive traversals in lib/dom.js that operate without a depth limit. When a sufficiently deeply nested DOM tree is encountered, it causes a RangeError: Maximum call stack size exceeded, resulting in the application crashing. This vulnerability can be exploited through a specially crafted XML document.
Defensive priority
High priority should be given to updating xmldom to versions 0.9.10 or 0.8.13. Developers should review their applications' dependency trees to ensure they are using a patched version of xmldom.
Recommended defensive actions
- Update xmldom to version 0.9.10 or 0.8.13
- Review application dependency trees for vulnerable xmldom versions
- Implement input validation for XML documents to prevent deeply nested structures
- Monitor applications for crashes or errors related to xmldom
- Consider using alternative XML parsing libraries with built-in protections
Evidence notes
The CVE-2026-41673 vulnerability was published on 2026-05-07 and last modified on 2026-07-01. The issue affects xmldom versions prior to 0.9.10 and 0.8.13. Red Hat has also addressed this vulnerability in their products, as indicated by their security advisories and errata.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-41673 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-41673
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-41673 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-41673
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/xmldom/xmldom/commit/17678a2a73ecbd1a2da90f3d47dc23da9cef81aa
-
Source reference
Unverified legacy reference
URL: https://github.com/xmldom/xmldom/commit/291257493cb0eb6980eda83b162a9c4e6d7d2597
-
Source reference
Unverified legacy reference
URL: https://github.com/xmldom/xmldom/commit/2d6d6916ed8a4c223db1f6d7560ab4544c465b0f
-
Source reference
Unverified legacy reference
URL: https://github.com/xmldom/xmldom/commit/430357c7b6333108856e917bf2367afe5ceb6f8a
-
Source reference
Unverified legacy reference
URL: https://github.com/xmldom/xmldom/commit/4845ef109221df0890825de2822fbe77afba3afe
-
Source reference
Unverified legacy reference
URL: https://github.com/xmldom/xmldom/commit/8834218c85ac2a4d757b9587c9028e67c2f7b6c3
-
Source reference
Unverified legacy reference
URL: https://github.com/xmldom/xmldom/commit/8b7cfd1491314abdc347261921d7334ff15f7112
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.