CVE-2026-25896 is a critical vulnerability affecting naturalintelligence fast-xml-parser versions 4.1.3 to before 5.3.5. It allows an attacker to bypass XML entity encoding by treating a dot in a DOCTYPE entity name as a regex wildcard, enabling the shadowing of built-in XML entities with arbitrary values. This can lead to Cross-Site Scripting (XSS) when the parsed output is rendered. Rated with a CVSS score of 9.3 (CRITICAL), this vulnerability has a low attack complexity and requires no user interaction, making it easily exploitable over the network. A successful exploit could lead to high impact on integrity and low impact on confidentiality. While there is no evidence of active exploitation, nor are there public exploit modules like Metasploit or Nuclei, the vulnerability has garnered significant community attention with over 25 mentions, indicating awareness and discussion within the cybersecurity community. The issue has been fixed in fast-xml-parser version 5.3.5.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.1.3, < 5.3.5CPE matchmatch criteria | cpe:2.3:a:naturalintelligence:fast-xml-parser:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.