VendorsNatural Intelligencefast-xml-parserany version
Vulnerabilities

Natural Intelligence fast-xml-parser any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2026-25896
fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names
Published 2026-02-20 · Modified
9.3EPSS 0.005
CVE-2023-34104
Regex Injection via Doctype Entities
Published 2023-06-06 · Modified
7.5EPSS 0.011
CVE-2026-26278
fast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit)
Published 2026-02-19 · Modified
7.5EPSS 0.010
CVE-2026-33036
fast-xml-parser affected by numeric entity expansion bypassing all entity expansion limits (incomplete fix for CVE-2026-26278)
Published 2026-03-20 · Analyzed
7.5EPSS 0.007
CVE-2026-27942
fast-xml-parser has stack overflow in XMLBuilder with preserveOrder
Published 2026-02-26 · Analyzed
7.5EPSS 0.006
CVE-2026-25128
fast-xml-parser has RangeError DoS Numeric Entities Bug
Published 2026-01-30 · Analyzed
7.5EPSS 0.006
CVE-2026-41650
fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters
Published 2026-05-07 · Analyzed
6.1EPSS 0.003
CVE-2026-33349
fast-xml-parser: Entity Expansion Limits Bypassed When Set to Zero Due to JavaScript Falsy Evaluation
Published 2026-03-24 · Analyzed
5.9EPSS 0.005