fast-xml-parser vulnerabilities
CVEs whose affected-version data names the fast-xml-parser package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
GHSA-8r6m-32jq-jx6qHighfast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits
fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits
CVE-2026-25896Critical· 9.3PoC⚖ disputedfast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard…
CVE-2026-26278High· 7.5fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.1.3 through 5.3.5, the XML parser can be forced to do an unlimited amount of e…