CVE-2026-33036: Naturalintelligence Fast-XML-Parser
High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.
fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Versions 4.0.0-beta.3 through 5.5.5 contain a bypass vulnerability where numeric character references (&#NNN;, &#xHH;) and standard XML entities completely evade the entity expansion limits (e.g., maxTotalExpansions, maxExpandedLength) added to fix CVE-2026-26278, enabling XML entity expansion Denial of Service. The root cause is that replaceEntitiesValue() in OrderedObjParser.js only enforces expansion counting on DOCTYPE-defined entities while the lastEntities loop handling numeric/standard entities performs no counting at all. An attacker supplying 1M numeric entity references like A can force ~147MB of memory allocation and heavy CPU usage, potentially crashing the process—even when developers have configured strict limits. This issue has been fixed in version 5.5.6.
Affected products
- Naturalintelligence Fast-XML-Parser: from 4.0.1, before 5.5.6 (fixed in 5.5.6); version 4.0.0 only
Published 2026-03-20. Last modified 2026-06-17.