fast-xml-parser
npm12 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting fast-xml-parserpage 1 of 1
- CVE-2021-26920MEDIUMCVSS 6.5EG 6.5fixed in 4.1.22021-07-02
In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with…
- CVE-2023-26920MEDIUMCVSS 6.5EG 6.5fixed in 4.1.22023-12-12
fast-xml-parser before 4.1.2 allows __proto__ for Prototype Pollution.
- CVE-2023-34104HIGHCVSS 7.5EG 7.5fixed in 4.2.42023-06-06
fast-xml-parser is an open source, pure javascript xml parser. fast-xml-parser allows special characters in entity names, which are not escaped or sanitized. Since the entity name is used for creating a regex for searching and replacing en…
- CVE-2024-41818HIGHCVSS 7.5EG 7.5fixed in 4.4.12024-07-29
fast-xml-parser is an open source, pure javascript xml parser. a ReDOS exists on currency.js. This vulnerability is fixed in 4.4.1.
- CVE-2026-25128HIGHCVSS 7.5EG 7.5fixed in 5.3.42026-01-30
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 5.0.9 through 5.3.3, a RangeError vulnerability exists in the numeric entity proce…
- CVE-2026-25896CRITICALCVSS 9.3EG 9.3fixed in 5.3.5 or 4.5.4, by version range2026-02-20
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard d…
- CVE-2026-26278HIGHCVSS 7.5EG 7.5fixed in 4.5.4 or 5.3.6, by version range2026-02-19
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.1.3 through 5.3.5, the XML parser can be forced to do an unlimited amount of ent…
- CVE-2026-27942LOWCVSS 2.7EG 2.7fixed in 5.3.8 or 4.5.4, by version range2026-02-26
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. Prior to version 5.3.8, the application crashes with stack overflow when user use XML builder …
- CVE-2026-33036HIGHCVSS 7.5EG 7.5fixed in 5.5.6 or 4.5.5, by version range2026-03-20
fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Versions 4.0.0-beta.3 through 5.5.5 contain a bypass vulnerability where numeric character references (&#NNN;, &#xHH;) and standard XML …
- CVE-2026-33349MEDIUMCVSS 5.9EG 5.9fixed in 4.5.5 or 5.5.7, by version range2026-03-24
fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From version 4.0.0-beta.3 to before version 5.5.7, the DocTypeReader in fast-xml-parser uses JavaScript truthy checks to evaluate maxEnt…
- CVE-2026-41650MEDIUMCVSS 6.1EG 6.1fixed in 5.7.02026-05-07
fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Prior to version 5.7.0, XMLBuilder does not escape the "-->" sequence in comment content or the "]]>" sequence in CDATA sections when bu…
- CVE-2026-73569HIGHCVSS 8.7EG 8.7fixed in 5.10.12026-07-21
fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From 5.9.3 until 5.10.1, src/xmlparser/OrderedObjParser.js processes multiple DOCTYPE declarations within a single XML document and pass…
Check whether fast-xml-parser is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for fast-xml-parser CVEs against the assets you own.
Book a Demo →