CVE-2026-25896: Entity Encoding Bypass in fast-xml-parser
Blog post from Endor Labs
A critical vulnerability identified as CVE-2026-25896 with a CVSS score of 9.3 has been found in the fast-xml-parser, a widely-used JavaScript/Node.js XML parsing library. This flaw, which affects versions >= 4.1.3 and < 5.3.5, allows attackers to exploit XML entity declarations to perform XSS and injection attacks by using a period (.) as a regex wildcard in a DOCTYPE entity name, thus shadowing built-in XML entities. The vulnerability persists despite an earlier fix for CVE-2023-34104, which missed addressing the period character, allowing it to bypass the patch. The vulnerability was disclosed on February 20, 2026, and a fix was released on February 8, 2026, with version 5.3.5 implementing the necessary safeguards, including escaping the dot character in entity names. Users are advised to upgrade to version 5.3.5 or later to mitigate the risk, or disable entity processing temporarily if an upgrade isn't immediately feasible. Additionally, implementing defense-in-depth practices such as output encoding and parameterized queries is recommended, along with configuring entity expansion limits and auditing XML processing patterns to prevent potential exploits.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.