VDB

CVE-2026-25896

CVE-2026-25896 PUBLISHED CVSS 9.300000190734863 CRITICAL

fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names

EPSS 0.02% · 5.7th percentile

Risk Scores

CVSS 3.1
9.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N
EPSS Score
0.02%
5.7th percentile

Affected Products

VendorProductVersions
NaturalIntelligencefast-xml-parser>= 5.0.0, < 5.3.5, *, >= 4.1.3, < 4.5.4
naturalintelligencefast-xml-parser4.1.3, 4.1.3
npmfast-xml-parser5.0.0, 4.1.3, 5.0.0

Timeline

  • Feb 20, 2026 CVE Published
  • Feb 20, 2026 PoC Published
  • Feb 21, 2026 EPSS Score
  • Feb 21, 2026 PoC Published
  • Feb 21, 2026 PoC Published
  • Feb 21, 2026 PoC Published
  • Feb 21, 2026 PoC Published
  • Feb 21, 2026 PoC Published
  • Feb 23, 2026 EPSS Score
  • Feb 24, 2026 EPSS Score
  • Feb 26, 2026 EPSS Score
  • Feb 27, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›