amit kumar gupta
12 exploits
Active since Jun 2023
fast-xml-parser < 4.2.4 - Denial of Service via Crafted Entity Name Regex
CVSS 7.5
fast-xml-parser >=4.3.5 <4.4.1 - Uncontrolled Resource Consumption via ReDOS in Currency Parser
CVSS 7.5
fast-xml-parser 4.1.3-5.3.4 - Cross-Site Scripting via DOCTYPE Entity Name Regex Bypass
CVSS 9.3
fast-xml-parser: Entity Expansion Limits Bypassed When Set to Zero Due to JavaScript Falsy Evaluation
CVSS 5.9
fast-xml-parser <5.5.6 - Numeric Entity Expansion Denial of Service
CVSS 7.5
fast-xml-parser < 5.3.8 - Denial of Service via XML Builder with preserveOrder:true
CVSS 7.5
fast-xml-parser 4.1.3-5.3.4 - Cross-Site Scripting via DOCTYPE Entity Name Regex Bypass
CVSS 9.3
fast-xml-parser 4.1.3-5.3.5 - XML External Entity Injection via Unrestricted Entity Expansion
CVSS 7.5
fast-xml-parser <4.1.2 - Info Disclosure
CVSS 6.5
fast-xml-parser < 4.2.4 - Denial of Service via Crafted Entity Name Regex
CVSS 7.5
fast-xml-parser >=4.3.5 <4.4.1 - Uncontrolled Resource Consumption via ReDOS in Currency Parser
CVSS 7.5
fast-xml-parser 5.0.9-5.3.3 - Denial of Service via Out-of-Range XML Entity Code Points
CVSS 7.5