CVE-2026-25896: Naturalintelligence Fast-XML-Parser
Critical severity, CVSS 9.3. EPSS: 0.5% chance of exploitation in the next 30 days.
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow built-in XML entities (<, >, &, ", ') with arbitrary values. This bypasses entity encoding and leads to XSS when parsed output is rendered. This vulnerability is fixed in 5.3.5.
Affected products
- Naturalintelligence Fast-XML-Parser: from 4.1.3, before 5.3.5 (fixed in 5.3.5)
Published 2026-02-20. Last modified 2026-09-10.