12 Total advisories
12 Vulnerabilities
0 Malware
Dependency scanning
Check whether fast-xml-parser is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
CVE-2026-73569
fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits
MEDIUM 6.1
CVE-2026-41650
fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters
MEDIUM 5.9
CVE-2026-33349
Entity Expansion Limits Bypassed When Set to Zero Due to JavaScript Falsy Evaluation in fast-xml-parser
HIGH 7.5
CVE-2026-33036
fast-xml-parser affected by numeric entity expansion bypassing all entity expansion limits (incomplete fix for CVE-2026-26278)
CRITICAL 9.3
CVE-2026-25896
fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names
HIGH 7.5
CVE-2026-26278
fast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit)
UNKNOWN
CVE-2026-27942
fast-xml-parser has stack overflow in XMLBuilder with preserveOrder
HIGH 7.5
CVE-2026-25128
fast-xml-parser has RangeError DoS Numeric Entities Bug
HIGH 7.5
CVE-2024-41818
fast-xml-parser vulnerable to ReDOS at currency parsing
MEDIUM 6.5
CVE-2021-26920
fast-xml-parser vulnerable to Prototype Pollution through tag or attribute name
HIGH 7.5
CVE-2023-34104
fast-xml-parser vulnerable to Regex Injection via Doctype Entities
UNKNOWN
GHSA-gpv5-7x3g-ghjv
fast-xml-parser regex vulnerability patch could be improved from a safety perspective
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes