Skip to content

Security Incident: Uncaught Exception in fast-xml-parser (CVE-2026-25128) #197

@lihue

Description

@lihue

The sitemapper project depends on fast-xml-parser@4.5.3, which contains a high-severity security vulnerability (CVE-2026-25128).
This issue allows an attacker to trigger an uncaught exception during XML parsing, potentially causing a Denial of Service (application crash).

The vulnerability was identified by Snyk and is currently rated CVSS 8.7 (High).

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions