Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-34104

22
FAUCET Score

CVE-2023-34104 is a Denial of Service (DoS) vulnerability affecting the fast-xml-parser library, where unescaped special characters in entity names can be abused to create a malicious regular expression, causing the parser to stall indefinitely. This vulnerability has a CVSS score of 7.5 (High), indicating it can be exploited remotely with low attack complexity, leading to a complete loss of availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the security community. Users are advised to upgrade to v4.2.4 or disable DOCTYPE parsing by setting processEntities: false.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.2.4CPE matchmatch criteria
cpe:2.3:a:naturalintelligence:fast-xml-parser:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.14%
Probability of exploitation in next 30 days
EPSS Percentile
63.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0114 is in the 41st percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: fast-xml-parserFixed in: 4.2.4
redhatpatch availablevia redhat_api
Product: MTA-6.2-RHEL-9Fixed in: mta/mta-ui-rhel9:6.2.0-17
View patch
redhatno patchvia redhat_api
Product: OpenShift ServerlessFixed in: org.kie.kogito-kogito-apps
redhatno patchvia redhat_api
Product: Red Hat OpenShift Virtualization 4Fixed in: container-native-virtualization/kubevirt-console-plugin
redhatno patchvia redhat_api
Product: Red Hat OpenShift Virtualization 4Fixed in: container-native-virtualization/kubevirt-console-plugin-rhel9

Vendor Advisories (2)

npmGHSA-6w63-h3fj-q4vwhigh

fast-xml-parser vulnerable to Regex Injection via Doctype Entities

Jun 6, 2023
redhatCVE-2023-34104Moderate

fast-xml-parser: Regex Injection via Doctype Entities

Jun 6, 2023

References

github.com / NaturalIntelligence/fast-xml-parser/commit/39b0e050bb909e8499478657f84a3076e39ce76c
Patch
github.com / NaturalIntelligence/fast-xml-parser/commit/a4bdced80369892ee413bf08e28b78795a2b0d5b
github.com / NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-6w63-h3fj-q4vw
MitigationVendor Advisory