CVE-2023-34104 is a Denial of Service (DoS) vulnerability affecting the fast-xml-parser library, where unescaped special characters in entity names can be abused to create a malicious regular expression, causing the parser to stall indefinitely. This vulnerability has a CVSS score of 7.5 (High), indicating it can be exploited remotely with low attack complexity, leading to a complete loss of availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the security community. Users are advised to upgrade to v4.2.4 or disable DOCTYPE parsing by setting processEntities: false.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.2.4CPE matchmatch criteria | cpe:2.3:a:naturalintelligence:fast-xml-parser:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.