VDB
Sign up

package

npm/fast-xml-parser

pkg:npm/fast-xml-parser

HIGH7.5npm
GHSA-8gc5-j5rx-235r· CVE-2026-33036

fast-xml-parser affected by numeric entity expansion bypassing all entity expansion limits (incomplete fix for CVE-2026-26278)

Modified: 9/10/2026

LOWnpm
GHSA-gpv5-7x3g-ghjv

fast-xml-parser regex vulnerability patch could be improved from a safety perspective

Modified: 6/15/2023