RangeError Vulnerability in fast-xml-parser Affects Natural Intelligence Software
CVE-2026-25128

7.5HIGH

Key Information:

Vendor
CVE Published:
30 January 2026

What is CVE-2026-25128?

The fast-xml-parser library, widely used for handling XML data, contains a RangeError vulnerability in versions 4.3.6 to 5.3.3. This issue occurs during the numeric entity processing phase when the parser encounters out-of-range entity code points like � or �. Such scenarios lead to uncaught exceptions that can crash applications relying on untrusted XML input. Users are encouraged to upgrade to version 5.3.4 or newer to mitigate this vulnerability and ensure stable XML processing.

Affected Version(s)

fast-xml-parser >= 5.0.9, <= 5.3.3

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.