CVE-2026-25896: fallo crítico en NaturalIntelligence fast-xml-parser
fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names
Publicada el · Actualizada el
28Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 9.3epss 0.5%
probabilidad de explotación
0.5%top 59% de las CVE
explotación observada
noninguna fuente lo reporta
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow built-in XML entities (<, >, &, ", ') with arbitrary values. This bypasses entity encoding and leads to XSS when parsed output is rendered. This vulnerability is fixed in 5.3.5.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N
Productos afectados
NaturalIntelligence · fast-xml-parserCVEs relacionadas — NaturalIntelligence fast-xml-parser
En el mismo producto, de las más peligrosas a las menos.
CVE-2023-34104HIGHRegex Injection via Doctype EntitiesEPSS 1.1%CVE-2026-26278HIGHfast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit)EPSS 1.0%CVE-2024-41818HIGHReDOS at currency parsing fast-xml-parserEPSS 0.8%CVE-2026-33036HIGHfast-xml-parser affected by numeric entity expansion bypassing all entity expansion limits (incomplete fix for CVE-2026-26278)EPSS 0.7%CVE-2026-27942LOWfast-xml-parser has stack overflow in XMLBuilder with preserveOrderEPSS 0.7%CVE-2026-25128HIGHfast-xml-parser has RangeError DoS Numeric Entities BugEPSS 0.6%
Referencias
https://access.redhat.com/errata/RHSA-2026:40984https://access.redhat.com/errata/RHSA-2026:41941https://access.redhat.com/errata/RHSA-2026:41944https://access.redhat.com/errata/RHSA-2026:51349https://access.redhat.com/errata/RHSA-2026:6174https://access.redhat.com/errata/RHSA-2026:6802https://access.redhat.com/errata/RHSA-2026:7110https://access.redhat.com/errata/RHSA-2026:7128https://access.redhat.com/security/cve/CVE-2026-25896https://bugzilla.redhat.com/show_bug.cgi?id=2441501https://github.com/NaturalIntelligence/fast-xml-parser/commit/943ef0eb1b2d3284e72dd74f44a042ee9f07026ehttps://github.com/NaturalIntelligence/fast-xml-parser/commit/ddcd0acf26ddd682cb0dc15a2bd6aa3b96bb1e69