VDB

CVE-2026-73569

CVE-2026-73569 PUBLISHED CVSS 8.7 HIGH

Reported by GitHub_M · Published August 13, 2026

fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From 5.9.3 until 5.10.1, src/xmlparser/OrderedObjParser.js processes multiple DOCTYPE declarations within a single XML document and passes each declaration's entities through addInputEntities(). addInputEntities() resets maxTotalExpansions and maxExpandedLength every time it is called, allowing additional DOCTYPE declarations to repeatedly reset the configured entity-expansion limits during one parse operation. A crafted XML document can then cause excessive CPU use, event-loop blocking, memory exhaustion, and process termination. This issue is fixed in version 5.10.1.

Risk Scores

CVSS 4.0
8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
NaturalIntelligencefast-xml-parser>= 5.9.3, < 5.10.1
chainguardjitsucom-jitsu0, 0, 0
chainguardlangfuse-fips-20, 0, 0
chainguardkibana-9.00, 0, 0
chainguardlangfuse-20, 0, 0
chainguardtileserver-gl-fips0, 0, 0
NaturalIntelligencefast-xml-parser>= 5.9.3, < 5.10.1
chainguardtileserver-gl0, 0, 0
chainguardthingsboard-fips0, 0, 0
chainguardkibana-9.20, 0, 0
wolfitileserver-gl0, 0, 0
wolfijitsucom-jitsu0, 0, 0

Timeline

  • Jul 21, 2026 CVE Published
  • Aug 13, 2026 Coalition ESS Score
  • Aug 13, 2026 CVE Updated
  • Aug 14, 2026 Security Advisory
  • Aug 24, 2026 EPSS Score
  • Aug 26, 2026 EPSS Score
  • Aug 30, 2026 EPSS Score
  • Sep 3, 2026 EPSS Score
  • Sep 7, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 16, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›