RangeError Vulnerability in fast-xml-parser Affects Natural Intelligence Software
CVE-2026-25128
7.5HIGH
What is CVE-2026-25128?
The fast-xml-parser library, widely used for handling XML data, contains a RangeError vulnerability in versions 4.3.6 to 5.3.3. This issue occurs during the numeric entity processing phase when the parser encounters out-of-range entity code points like � or �. Such scenarios lead to uncaught exceptions that can crash applications relying on untrusted XML input. Users are encouraged to upgrade to version 5.3.4 or newer to mitigate this vulnerability and ensure stable XML processing.
Affected Version(s)
fast-xml-parser >= 5.0.9, <= 5.3.3
