CVE-2026-33036 is a high-severity Denial of Service vulnerability affecting fast-xml-parser versions 4.0.0-beta.3 through 5.5.5, where numeric and standard XML entities can bypass configured expansion limits. This allows an attacker to trigger excessive memory allocation and CPU usage, potentially crashing the process. Rated 7.5 CVSS, it is remotely exploitable with low complexity and no user interaction or privileges required, primarily impacting system availability. There is no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.1, < 5.5.6CPE matchmatch criteria | cpe:2.3:a:naturalintelligence:fast-xml-parser:*:*:*:*:*:*:*:* | ||
4.0.0CPE matchmatch criteria | cpe:2.3:a:naturalintelligence:fast-xml-parser:4.0.0:-:*:*:*:*:*:* | ||
4.0.0CPE matchmatch criteria | cpe:2.3:a:naturalintelligence:fast-xml-parser:4.0.0:beta3:*:*:*:*:*:* | ||
4.0.0CPE matchmatch criteria | cpe:2.3:a:naturalintelligence:fast-xml-parser:4.0.0:beta4:*:*:*:*:*:* | ||
4.0.0CPE matchmatch criteria | cpe:2.3:a:naturalintelligence:fast-xml-parser:4.0.0:beta5:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.