Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33036

28
FAUCET Score

CVE-2026-33036 is a high-severity Denial of Service vulnerability affecting fast-xml-parser versions 4.0.0-beta.3 through 5.5.5, where numeric and standard XML entities can bypass configured expansion limits. This allows an attacker to trigger excessive memory allocation and CPU usage, potentially crashing the process. Rated 7.5 CVSS, it is remotely exploitable with low complexity and no user interaction or privileges required, primarily impacting system availability. There is no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.0.1, < 5.5.6CPE matchmatch criteria
cpe:2.3:a:naturalintelligence:fast-xml-parser:*:*:*:*:*:*:*:*
4.0.0CPE matchmatch criteria
cpe:2.3:a:naturalintelligence:fast-xml-parser:4.0.0:-:*:*:*:*:*:*
4.0.0CPE matchmatch criteria
cpe:2.3:a:naturalintelligence:fast-xml-parser:4.0.0:beta3:*:*:*:*:*:*
4.0.0CPE matchmatch criteria
cpe:2.3:a:naturalintelligence:fast-xml-parser:4.0.0:beta4:*:*:*:*:*:*
4.0.0CPE matchmatch criteria
cpe:2.3:a:naturalintelligence:fast-xml-parser:4.0.0:beta5:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.58%
Probability of exploitation in next 30 days
EPSS Percentile
44.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0058 is in the 21st percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (18)

npmpatch availablevia ghsa
Product: fast-xml-parserFixed in: 5.5.6
npmpatch availablevia ghsa
Product: fast-xml-parserFixed in: 4.5.5
redhatno patchvia redhat_api
Product: Migration Toolkit for Applications 8Fixed in: mta/mta-ui-rhel9
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Security 4Fixed in: advanced-cluster-security/rhacs-main-rhel8
redhatno patchvia redhat_api
Product: Red Hat Developer HubFixed in: rhdh/backstage-community-plugin-catalog-backend-module-scaffolder-relation-processor
redhatno patchvia redhat_api
Product: Red Hat Developer HubFixed in: rhdh/rhdh-hub-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-mlflow-rhel9
redhatno patchvia redhat_api
Product: Red Hat Openshift Data Foundation 4Fixed in: odf4/mcg-core-rhel9
redhatno patchvia redhat_api
Product: Red Hat Openshift Data Foundation 4Fixed in: odf4/ocs-client-console-rhel9
redhatno patchvia redhat_api
Product: Red Hat Openshift Data Foundation 4Fixed in: odf4/odf-console-rhel9
redhatno patchvia redhat_api
Product: Red Hat Openshift Data Foundation 4Fixed in: odf4/odf-multicluster-console-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift GitOpsFixed in: openshift-gitops-1/argocd-rhel8
redhatno patchvia redhat_api
Product: Red Hat OpenShift GitOpsFixed in: openshift-gitops-1/argocd-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift Virtualization 4Fixed in: container-native-virtualization/kubevirt-console-plugin
redhatno patchvia redhat_api
Product: Red Hat OpenShift Virtualization 4Fixed in: container-native-virtualization/kubevirt-console-plugin-rhel9
redhatno patchvia redhat_api
Product: Red Hat Satellite 6Fixed in: satellite/iop-host-inventory-frontend-rhel9
redhatno patchvia redhat_api
Product: Red Hat Satellite 6Fixed in: satellite/iop-vulnerability-frontend-rhel9
redhatno patchvia redhat_api
Product: Self-service automation portal 2Fixed in: ansible-automation-platform/automation-portal

Vendor Advisories (2)

redhatCVE-2026-33036Moderate

fast-xml-parser: fast-xml-parser: Denial of Service via XML entity expansion bypass

Mar 20, 2026
npmGHSA-8gc5-j5rx-235rhigh

fast-xml-parser affected by numeric entity expansion bypassing all entity expansion limits (incomplete fix for CVE-2026-26278)

Mar 17, 2026

References

github.com / NaturalIntelligence/fast-xml-parser/commit/bd26122c838e6a55e7d7ac49b4ccc01a49999a01
Patch
github.com / NaturalIntelligence/fast-xml-parser/releases/tag/v5.5.6
ProductRelease Notes
github.com / NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-8gc5-j5rx-235r
ExploitMitigationVendor Advisory