
Node.js DoS flaw CVE-2026-26278 in fast-xml-parser freezes event loops via XML entity expansion. 46M weekly downloads affected. Update to version 5.3.6. #NodeJS #CyberSecurity #CVE202626278 #InfoSec #fastxmlparser #AppSec #npm https://securityonline.info/high-severity-dos-flaw-hits-46-million-fast-xml-parser-downloads/
Post summary
CVE‑2026‑26278 is a DoS vulnerability in fast‑xml‑parser that freezes event loops via XML entity expansion, affecting 46 million weekly downloads; updating to version 5.3.6 mitigates the issue.


