CVE-2026-25896 PUBLISHED CVSS 9.300000190734863 CRITICAL

fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names

EPSS 0.01% · 2.5th percentile

Risk Scores

CVSS v3.1
9.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N
EPSS Score
0.01%
2.5th percentile

Affected Products

VendorProductVersions
NaturalIntelligencefast-xml-parser>= 5.0.0, < 5.3.5, >= 4.1.3, < 4.5.4, >= 5.0.0, < 5.3.5
naturalintelligencefast-xml-parser4.1.3, 4.1.3
npmfast-xml-parser5.0.0, 4.1.3, 5.0.0

Timeline

References

Open in Interactive Console →