CVE-2026-25896
The fast‑xml‑parser library can be tricked into replacing standard XML entities with attacker‑controlled values, allowing malicious scripts to be injected into parsed XML. This flaw exists in versions 4.1.3 through 5.3.4 and can be exploited when the parsed output is rendered in a web application.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
The naturalintelligence fast‑xml‑parser library, versions 4.1.3 to 5.3.4, used in Node.js applications.
Real-world impact
An attacker could embed malicious JavaScript into XML data that, when parsed and displayed by a web application, would run in the victim’s browser, enabling cross‑site scripting attacks.
Why this severity
The CVSS score of 9.3 reflects that the vulnerability is network‑exploitable with no authentication or user interaction, and it can compromise the confidentiality of the attacker’s data (high impact).
What to do about it
- 01Upgrade fast-xml-parser to version 5.3.5 or later.
NVD-referenced vendor advisory
Timeline
- Feb 20, 2026 · Feb 20, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 20, 2026 · 16d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 21, 2026 · 15d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- github.com/NaturalIntelligence/fast-xm…patch
- github.com/NaturalIntelligence/fast-xm…patch
- github.com/NaturalIntelligence/fast-xm…productrelease notes
- github.com/NaturalIntelligence/fast-xm…exploitmitigationvendor advisory
- access.redhat.com/errata/RHSA-2026:40984
- access.redhat.com/errata/RHSA-2026:41941
- access.redhat.com/errata/RHSA-2026:41944
- access.redhat.com/errata/RHSA-2026:6174
- access.redhat.com/errata/RHSA-2026:6802
- access.redhat.com/errata/RHSA-2026:7110
- access.redhat.com/errata/RHSA-2026:7128
- access.redhat.com/security/cve/CVE-2026-25896
- bugzilla.redhat.com/show_bug.cgi
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2…