CVE-2026-25896
CRITICALfast-xml-parser 4.1.3-5.3.4 - Cross-Site Scripting via DOCTYPE Entity Name Regex Bypass
Title source: llmDescription
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow built-in XML entities (<, >, &, ", ') with arbitrary values. This bypasses entity encoding and leads to XSS when parsed output is rendered. This vulnerability is fixed in 5.3.5.
References (14)
Core 14
Core References
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:40984
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:6174
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:6802
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:7110
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:7128
Vendor Advisory
https://access.redhat.com/security/cve/CVE-2026-25896
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2441501
Vendor Advisory x_refsource_confirm
https://github.com/NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-m7jm-9gc2-mpf2
Patch x_refsource_misc
https://github.com/NaturalIntelligence/fast-xml-parser/commit/943ef0eb1b2d3284e72dd74f44a042ee9f07026e
Patch x_refsource_misc
https://github.com/NaturalIntelligence/fast-xml-parser/commit/ddcd0acf26ddd682cb0dc15a2bd6aa3b96bb1e69
Release Notes x_refsource_misc
https://github.com/NaturalIntelligence/fast-xml-parser/releases/tag/v5.3.5
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:41941
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:41944
Scores
CVSS v3
9.3
EPSS
0.0046
EPSS Percentile
37.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-185
CWE-79
Status
published
Products (4)
naturalintelligence/fast-xml-parser
4.1.3 - 5.3.5
NaturalIntelligence/fast-xml-parser
>= 4.1.3, < 4.5.4
NaturalIntelligence/fast-xml-parser
>= 5.0.0, < 5.3.5
npm/fast-xml-parser
5.0.0 - 5.3.5npm
Published
Feb 20, 2026
Tracked Since
Feb 21, 2026