Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
Jobs
Pricing
EN
中
Loading…
npm/fast-xml-parser — 10 CVEs · VulnScope
pkg:npm/
fast-xml-parser
10 total CVEs
CRITICAL
1
HIGH
6
MEDIUM
3
✅ Check your installed version
Check
All known vulnerabilities
CRITICAL
9.3
CVE-2026-25896
fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names
>= 5.0.0, < 5.3.5
HIGH
7.5
CVE-2026-33036
fast-xml-parser affected by numeric entity expansion bypassing all entity expansion limits (incomplete fix for CVE-2026-26278)
>= 5.0.0, < 5.5.6
HIGH
7.5
CVE-2026-27942
fast-xml-parser has stack overflow in XMLBuilder with preserveOrder
>= 5.0.0, < 5.3.8
HIGH
7.5
fast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit)
>= 4.1.3, < 4.5.4
HIGH
7.5
fast-xml-parser has RangeError DoS Numeric Entities Bug
>= 5.0.9, < 5.3.4
HIGH
7.5
fast-xml-parser vulnerable to ReDOS at currency parsing
>= 4.3.5, < 4.4.1
HIGH
7.5
fast-xml-parser vulnerable to Regex Injection via Doctype Entities
>= 4.1.3, < 4.2.4
MEDIUM
6.5
fast-xml-parser vulnerable to Prototype Pollution through tag or attribute name
from 0, < 4.1.2
MEDIUM
6.1
fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters
from 0, < 5.7.0
MEDIUM
5.9
Entity Expansion Limits Bypassed When Set to Zero Due to JavaScript Falsy Evaluation in fast-xml-parser
>= 4.0.0-beta.3, < 4.5.5
CVE-2026-26278
CVE-2026-25128
CVE-2024-41818
CVE-2023-34104
CVE-2023-26920
CVE-2026-41650
CVE-2026-33349