CVE-2026-25896Patch(naturalintelligence / fast-xml-parser)

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch naturalintelligence fast-xml-parser systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow built-in XML entities (<, >, &, ", ') with arbitrary values. This bypasses entity encoding and leads to XSS when parsed output is rendered. This vulnerability is fixed in 5.3.5.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-185CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fast-xml-parser

Threat summary

  • Patch or workaround signal is available
  • 11 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 8 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 5d ago at 5 mentions (2026-02-20); latest day: 2
  • 11 total mentions across 6 days

Affected systems

Products
fast-xml-parser

Deep dive

Activity timeline11 mentions / 6d
01345Mentions · 2026-02-20: 5Mentions · 2026-02-21: 1Mentions · 2026-02-23: 1Mentions · 2026-02-24: 1Mentions · 2026-02-28: 1Mentions · 2026-09-01: 2Patch / Workaround · 2026-02-20: 2Patch / Workaround · 2026-02-21: 1Patch / Workaround · 2026-02-23: 1Patch / Workaround · 2026-02-24: 1Patch / Workaround · 2026-02-28: 1Patch / Workaround · 2026-09-01: 1Technical Details · 2026-02-20: 4Technical Details · 2026-02-21: 1Technical Details · 2026-02-23: 1Technical Details · 2026-02-24: 1Technical Details · 2026-09-01: 102-2002-2102-2302-2402-2809-01
Signal classification3 categories
Patch
763.6%
Disclosure
327.3%
General
19.1%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-02-205
Disclosure3Patch2
2026-02-211
Patch1
2026-02-231
Patch1
2026-02-241
Patch1
2026-02-281
Patch1
2026-09-012
General1Patch1
Full discourse11 posts
  • CVE Brief@DailyCVEBrief
    Patch

    LOOK BACK — In 2023 fast-xml-parser fixed a regex-injection bug by blacklisting metacharacters in DOCTYPE entity names. It missed the dot, which XML allows in a name. Three years on: CVE-2026-25896, an entity named l. shadows < and defeats output encoding. https://t.co/GuYGyvKJUW

    Post summary

    The tweet is a retrospective note on the fast‑xml‑parser regex‑injection fix, highlighting a missed dot case and referencing CVE‑2026‑25896.

    1000040
    31 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: A critical incorrect regular expression vulnerability in #fastxmlparser enables XSS and injection via crafted XML inputs. #CVE-2026-25896 CVSS: 9.3. #Patch #Patch #Patch. More info: https://github.com/NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-m7jm-9gc2-mpf2

    Post summary

    The advisory warns of a critical regex flaw in fastxmlparser that permits XSS and injection, assigns a CVSS of 9.3, and directs users to apply the available patch.

    00001242
    7.2K followersView on X
  • CVE Brief@DailyCVEBrief
    General

    Full Look Back: the incomplete 2023 fix, the advisory that told every 4.x user there was no patch on their branch, and why NVD carries a 9.3 and a 7.1 side by side. https://cvebrief.com/cve/CVE-2026-25896/ https://t.co/vmIGZx12Im

    Post summary

    The tweet highlights that CVE‑2026‑25896 had an incomplete 2023 fix, no patch for 4.x, and differing NVD scores, but it provides no technical specifics or exploitation evidence.

    0000034
    31 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2026-25896 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/429 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    AWS Lambda base images have been updated to remove CVE-2026-25896, indicating the vulnerability has been patched or mitigated.

    0000048
    30 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A vulnerability (CVE-2026-25896) in `fast-xml-parser`, used by `node-webfont`, presents a denial of service risk from crafted XML. Patching `fast-xml-parser` to 5.3.5+ is advised. #XML #NodeJS #Security https://www.pulsepatch.io/posts/cve-2026-25896-fast-xml-parser-node-webfont-regex-vulnerability

    Post summary

    CVE-2026-25896 is a denial‑of‑service vulnerability in fast‑xml‑parser used by node‑webfont; patching to version 5.3.5+ is recommended.

    0000053
    1 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: fast-xml-parser (<5.3.5) lets attackers override XML entities — leads to XSS! Web apps using affected versions are at risk. Upgrade now to 5.3.5+ for protection. https://radar.offseq.com/threat/cve-2026-25896-cwe-185-incorrect-regular-expressio-a786da3a #OffSeq #XS... https://t.co/FgvC7c414t

    Post summary

    The tweet warns that fast‑xml‑parser versions below 5.3.5 are vulnerable to XSS, and urges updating to 5.3.5+ to mitigate CVE‑2026‑25896.

    0000035
    265 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25896 fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5… https://www.cve.org/CVERecord?id=CVE-2026-25896

    Post summary

    The text reveals that CVE‑2026‑25896 impacts fast‑xml‑parser, enabling XML validation, parsing, and building without C/C++ libraries or callbacks, affecting versions 4.1.3 up to before 5.

    0000097
    56.4K followersView on X
  • Säkerhetsbloggen@Sakerhetsblogg
    Patch

    CVE-2026-25896 i fast-xml-parser tillåter angripare att skugga inbyggda XML-enheter och exekvera skadlig kod via XSS. Uppgradera till version 5.3.5 för att skydda dig. #säkerhet #cybersäkerhet #CVE

    Post summary

    CVE-2026-25896 is an XSS vulnerability in fast‑xml‑parser that lets attackers shadow XML entities to run malicious code; a patch is available in version 5.3.5, and users are urged to upgrade.

    0000019
    7 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-25896: CRITICAL] Critical security update! Update fast-xml-parser to version 5.3.5 to fix a vulnerability allowing attackers to shadow built-in XML entities, leading to XSS attacks. #cybersecurity#cve,CVE-2026-25896,#cybersecurity https://cvefind.com/CVE-2026-25896

    Post summary

    The text announces a critical CVE in fast-xml-parser, notes an XSS flaw caused by shadowing XML entities, and directs users to update to version 5.3.5 for a fix.

    0000037
    578 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-25896** pertains to a critical security flaw in the `fast-xml-parser` JavaScript library, specifically affecting versions **from 4.1.3 up to but not including 5.3.5**. The vulnerability arises from improper handling of DOCTYPE entity names during XML parsing, where a dot (`.`) within an entity name is treated as a regex wildcard during entity replacement. This behavior allows an attacker to shadow or override built-in XML entities (such as `<`, `>`, `&`, `"`, `'`) with arbitrary values. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #XSS https://cvetodo.com/cve/CVE-2026-25896

    Post summary

    The post discloses a critical flaw in fast-xml-parser involving DOCTYPE entity name handling that could allow entity overriding, without referencing exploits or patches.

    0000035
    20 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-25896: Regex Injection in fast-xml-parser: Shadowing the < A critical regex injection vulnerability exists in the `fast-xml-parser` library (versions 4.1.3 to <5.3.5). The parser constructs regular expressions dynamically from untrusted DO... https://cvereports.com/reports/CVE-2026-25896

    Post summary

    The snippet reports a critical regex injection flaw in the fast-xml-parser library (v4.1.3 to <5.3.5) without mentioning a PoC, exploit code, active attacks, or a patch—representing a pure vulnerability disclosure.

    0000037
    26 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnaturalintelligencefast-xml-parser---

Explore more