CVE-2026-33036Disclosure(naturalintelligence / fast-xml-parser)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Versions 4.0.0-beta.3 through 5.5.5 contain a bypass vulnerability where numeric character references (&#NNN;, &#xHH;) and standard XML entities completely evade the entity expansion limits (e.g., maxTotalExpansions, maxExpandedLength) added to fix CVE-2026-26278, enabling XML entity expansion Denial of Service. The root cause is that replaceEntitiesValue() in OrderedObjParser.js only enforces expansion counting on DOCTYPE-defined entities while the lastEntities loop handling numeric/standard entities performs no counting at all. An attacker supplying 1M numeric entity references like A can force ~147MB of memory allocation and heavy CPU usage, potentially crashing the process—even when developers have configured strict limits. This issue has been fixed in version 5.5.6.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-776

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fast-xml-parser

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-18); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
fast-xml-parser

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-18: 1Mentions · 2026-03-20: 1Technical Details · 2026-03-20: 103-1803-20
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-181
Disclosure1
2026-03-201
General1
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-33036 fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Versions 4.0.0-beta.3 through 5.5.5 contain a bypass vulnerabil… https://www.cve.org/CVERecord?id=CVE-2026-33036

    Post summary

    The post provides a brief technical description of CVE‑2026‑33036, noting the vulnerability type and affected versions, but lacks any mention of a PoC, exploit code, active exploitation, or patch information.

    0000062
    56.8K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 fast-xml-parser, Improper Restriction of Numeric Entity Expansion (#CVE-2026-33036) (Critical) https://dailycve.com/fast-xml-parser-improper-restriction-of-numeric-entity-expansion-cve-2026-33036-critical/

    Post summary

    An article announces a critical vulnerability (CVE-2026-33036) affecting fast-xml-parser, characterized by improper numeric entity expansion, but provides no further technical or exploit details.

    0000029
    169 followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
Appnaturalintelligencefast-xml-parser---
Appnaturalintelligencefast-xml-parser4.0.0--
Appnaturalintelligencefast-xml-parser4.0.0--
Appnaturalintelligencefast-xml-parser4.0.0--
Appnaturalintelligencefast-xml-parser4.0.0--
Appnaturalintelligencefast-xml-parser4.0.0--
Appnaturalintelligencefast-xml-parser4.0.0--
Appnaturalintelligencefast-xml-parser4.0.0--

Explore more