Skip to content

Commit 2c8ca23

Browse files
authored
Merge pull request #291 from iteratehq/mike/CVE-2026-26278
fix: resolve CVE-2026-26278 fast-xml-parser DoS vulnerability
2 parents 0014f2f + 0d30b52 commit 2c8ca23

2 files changed

Lines changed: 11 additions & 10 deletions

File tree

package.json

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -85,7 +85,8 @@
8585
"@types/react": "^18.0.0 || ^19.0.0",
8686
"glob": "^10.5.0",
8787
"qs": "^6.14.0",
88-
"tar": "^7.5.3"
88+
"tar": "^7.5.3",
89+
"fast-xml-parser": "^5.3.6"
8990
},
9091
"peerDependencies": {
9192
"react": ">=18.0.0",

yarn.lock

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -6130,14 +6130,14 @@ __metadata:
61306130
languageName: node
61316131
linkType: hard
61326132

6133-
"fast-xml-parser@npm:^4.4.1":
6134-
version: 4.5.3
6135-
resolution: "fast-xml-parser@npm:4.5.3"
6133+
"fast-xml-parser@npm:^5.3.6":
6134+
version: 5.3.7
6135+
resolution: "fast-xml-parser@npm:5.3.7"
61366136
dependencies:
6137-
strnum: ^1.1.1
6137+
strnum: ^2.1.2
61386138
bin:
61396139
fxparser: src/cli/cli.js
6140-
checksum: cd6a184941ec6c23f9e6b514421a3f396cfdff5f4a8c7c27bd0eff896edb4a2b55c27da16f09b789663613dfc4933602b9b71ac3e9d1d2ddcc0492fc46c8fa52
6140+
checksum: 0bb307bc63a01c079ae28b6b62eeea0007d787e6ab47dfca493f40305f78aeedea2906b2632bf0eb9d4d868e748c77c70393a808441fb5949c9d2e6f8f2825f0
61416141
languageName: node
61426142
linkType: hard
61436143

@@ -11488,10 +11488,10 @@ __metadata:
1148811488
languageName: node
1148911489
linkType: hard
1149011490

11491-
"strnum@npm:^1.1.1":
11492-
version: 1.1.2
11493-
resolution: "strnum@npm:1.1.2"
11494-
checksum: a85219eda13e97151c95e343a9e5960eacfb0a0ff98104b4c9cb7a212e3008bddf0c9714c9c37c2e508be78e741a04afc80027c2dc18509d1b5ffd4c37191fc2
11491+
"strnum@npm:^2.1.2":
11492+
version: 2.1.2
11493+
resolution: "strnum@npm:2.1.2"
11494+
checksum: 755e8327ee68201d700169ceee097ea52da7b675f4521442a8dbd1517021f89a91399213c446d1bf3d1123ca1896a76f0ff076d04c88ffe6056e78828ce6f60a
1149511495
languageName: node
1149611496
linkType: hard
1149711497

0 commit comments

Comments
 (0)