PT-2026-25995 · Unknown · Fast-Xml-Parser

Deprrous

·

Published

2026-03-17

·

Updated

2026-05-06

·

CVE-2026-33036

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions fast-xml-parser versions 4.0.0-beta.3 through 5.5.5
Description fast-xml-parser allows users to process XML from JavaScript objects without relying on C/C++ based libraries or callbacks. Versions 4.0.0-beta.3 through 5.5.5 contain a bypass that allows numeric character references (&#NNN;, &#xHH;) and standard XML entities to circumvent entity expansion limits (like maxTotalExpansions and maxExpandedLength) originally implemented to address CVE-2026-26278. This bypass enables a denial of service through XML entity expansion. The root cause is that the replaceEntitiesValue() function in OrderedObjParser.js only enforces expansion counting on entities defined in DOCTYPE, while the loop handling numeric and standard entities does not perform any counting. An attacker can supply a large number of numeric entity references, such as 1M instances of A, to force significant memory allocation (approximately 147MB) and high CPU usage, potentially crashing the process even with strict limits configured.
Recommendations fast-xml-parser versions prior to 5.5.6 are affected. Update to version 5.5.6 or later to resolve this issue.

Exploit

Fix

XML Entity Expansion

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-DV49099
CLEANSTART-2026-GS57401
CLEANSTART-2026-SW34937
CVE-2026-33036
GHSA-8GC5-J5RX-235R
OPENSUSE-SU-2026:10462-1

Affected Products

Fast-Xml-Parser