CVE-2026-25896
🔴 Łataj teraz
Błąd w fast-xml-parser umożliwia atak XSS przez nieprawidłowe przetwarzanie encji XML.
CVSS
9.3
EPSS
0.5%
Exploit
poc
Vendor
naturalintelligence
Opis źródłowy (NVD)
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow built-in XML entities (<, >, &, ", ') with arbitrary values. This bypasses entity encoding and leads to XSS when parsed output is rendered. This vulnerability is fixed in 5.3.5.
exploit xss
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.3 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.5% |
| Opublikowano (NVD) | 2026-02-20 21:19:27 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-24 13:17:48 UTC |
Referencje
- https://github.com/NaturalIntelligence/fast-xml-parser/commit/943ef0eb1b2d3284e72dd74f44a042ee9f07026e (security-advisories@github.com) [Patch]
- https://github.com/NaturalIntelligence/fast-xml-parser/commit/ddcd0acf26ddd682cb0dc15a2bd6aa3b96bb1e69 (security-advisories@github.com) [Patch]
- https://github.com/NaturalIntelligence/fast-xml-parser/releases/tag/v5.3.5 (security-advisories@github.com) [Product, Release Notes]
- https://github.com/NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-m7jm-9gc2-mpf2 (security-advisories@github.com) [Exploit, Mitigation, Vendor Advisory]
- https://access.redhat.com/errata/RHSA-2026:40984 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:41941 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:41944 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:51349 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:6174 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:6802 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:7110 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:7128 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/security/cve/CVE-2026-25896 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://bugzilla.redhat.com/show_bug.cgi?id=2441501 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25896.json (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)