Naturalintelligence maintains the fast-xml-parser library, a widely adopted XML parsing component embedded across many downstream applications and services, where its vulnerability surface reflects the inherent complexity of XML processing and input validation. The recurring exposure centers on XML entity expansion attacks, uncontrolled resource consumption, regular expression complexity, and buffer-handling issues—weakness classes characteristic of parsing libraries that must balance performance with strict input bounds and entity constraint enforcement. Defenders should inventory products that bundle this library and treat parser updates as part of supply-chain risk management; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Naturalintelligence over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-25896CRITICAL fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (. | Feb 20, 2026 | 9.3 | 39 | NO | NO |
CVE-2026-26278HIGH fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.1.3 through 5.3.5, th | Feb 19, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-27942HIGH fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. Prior to version 5.3.8, the applica | Feb 26, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-33036HIGH fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Versions 4.0.0-beta.3 through 5.5.5 contain a bypass vulnerability where nume | Mar 20, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-25128HIGH fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 5.0.9 through 5.3.3, a | Jan 30, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-41650MEDIUM fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Prior to version 5.7.0, XMLBuilder does not escape the "-->" sequence in comm | May 7, 2026 | 6.1 | 26 | NO | NO |
CVE-2026-33349MEDIUM fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From version 4.0.0-beta.3 to before version 5.5.7, the DocTypeReader in fast- | Mar 24, 2026 | 5.9 | 22 | NO | NO |
CVE-2024-41818HIGH fast-xml-parser is an open source, pure javascript xml parser. a ReDOS exists on currency.js. This vulnerability is fixed in 4.4.1. | Jul 29, 2024 | 7.5 | 22 | NO | NO |
CVE-2023-34104HIGH fast-xml-parser is an open source, pure javascript xml parser. fast-xml-parser allows special characters in entity names, which are not escaped or sanitized. Since the entity name | Jun 6, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-26920MEDIUM fast-xml-parser before 4.1.2 allows __proto__ for Prototype Pollution. | Dec 12, 2023 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Naturalintelligence.
Media articles that mention a CVE ID that affects a product developed by Naturalintelligence — matched by CVE ID, not by vendor name.