CVE-2026-26278Patch(naturalintelligence / fast-xml-parser)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch naturalintelligence fast-xml-parser systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.1.3 through 5.3.5, the XML parser can be forced to do an unlimited amount of entity expansion. With a very small XML input, it’s possible to make the parser spend seconds or even minutes processing a single request, effectively freezing the application. Version 5.3.6 fixes the issue. As a workaround, avoid using DOCTYPE parsing by `processEntities: false` option.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-776

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fast-xml-parser

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-20); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
fast-xml-parser

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-19: 1Mentions · 2026-02-20: 2Mentions · 2026-02-28: 1Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-02-28: 1Technical Details · 2026-02-19: 102-1902-2002-28
Signal classification3 categories
Patch
250.0%
Disclosure
125.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-191
Patch1
2026-02-202
Disclosure1General1
2026-02-281
Patch1
Full discourse4 posts
  • Gray Hats@the_yellow_fall
    Patch

    Node.js DoS flaw CVE-2026-26278 in fast-xml-parser freezes event loops via XML entity expansion. 46M weekly downloads affected. Update to version 5.3.6. #NodeJS #CyberSecurity #CVE202626278 #InfoSec #fastxmlparser #AppSec #npm https://securityonline.info/high-severity-dos-flaw-hits-46-million-fast-xml-parser-downloads/

    Post summary

    CVE‑2026‑26278 is a DoS vulnerability in fast‑xml‑parser that freezes event loops via XML entity expansion, affecting 46 million weekly downloads; updating to version 5.3.6 mitigates the issue.

    00011176
    10.3K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2026-26278 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/426 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    The post indicates that CVE-2026-26278 has been removed from the latest AWS Lambda base images, suggesting a patch or update has addressed the vulnerability.

    0000046
    30 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New HIGH CVE detected in AWS Lambda 🚨 CVE-2026-26278 impacts fast-xml-parser in 4 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/426 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A new high‑severity CVE, CVE-2026‑26278, has been identified in the fast‑xml‑parser library used by four AWS Lambda base images. Links to a GitHub issue and additional information are provided for further details.

    0000027
    30 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-26278 fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.1.3 thr… https://www.cve.org/CVERecord?id=CVE-2026-26278

    Post summary

    The entry simply references CVE‑2026‑26278 and provides a link to its record, without additional technical or exploit details.

    00000526
    56.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnaturalintelligencefast-xml-parser---

Explore more