Skip to content

SNOW-3043109: chore: bump fast-xml-parser to ^5 #1251

@benknoble

Description

@benknoble

The snowflake-sdk package depends on an old version of fast-xml-parser, which is vulnerable to CVE-2026-25128.

(The transitive dependency @google-cloud/storage is also vulnerable; a PR fix is available.)

Currently this requires using overrides in downstream consumers, which is not ideal.

Metadata

Metadata

Labels

bugSomething isn't workingstatus-fixed_awaiting_releaseThe issue has been fixed, its PR merged, and now awaiting the next release cycle of the connector.status-triage_doneInitial triage done, will be further handled by the driver team

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions