Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

CVE-2026-25896: Entity Encoding Bypass in fast-xml-parser

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Peyton Kennedy
Word Count
851
Company Posts That Month
16
Language
English
Hacker News Points
-
Post removed?
No
Summary

A critical vulnerability identified as CVE-2026-25896 with a CVSS score of 9.3 has been found in the fast-xml-parser, a widely-used JavaScript/Node.js XML parsing library. This flaw, which affects versions >= 4.1.3 and < 5.3.5, allows attackers to exploit XML entity declarations to perform XSS and injection attacks by using a period (.) as a regex wildcard in a DOCTYPE entity name, thus shadowing built-in XML entities. The vulnerability persists despite an earlier fix for CVE-2023-34104, which missed addressing the period character, allowing it to bypass the patch. The vulnerability was disclosed on February 20, 2026, and a fix was released on February 8, 2026, with version 5.3.5 implementing the necessary safeguards, including escaping the dot character in entity names. Users are advised to upgrade to version 5.3.5 or later to mitigate the risk, or disable entity processing temporarily if an upgrade isn't immediately feasible. Additionally, implementing defense-in-depth practices such as output encoding and parameterized queries is recommended, along with configuring entity expansion limits and auditing XML processing patterns to prevent potential exploits.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.