Denial of Service Vulnerability in fast-xml-parser by Natural Intelligence
CVE-2026-33036
7.5HIGH
What is CVE-2026-33036?
Fast-xml-parser is susceptible to a Denial of Service vulnerability that allows attackers to exploit numeric character references and standard XML entities. This issue arises because the entity count checks only apply to DOCTYPE-defined entities, allowing unregulated numeric and standard entities. By supplying a large number of numeric entity references, attackers can trigger significant memory consumption and CPU load, potentially crashing services even with strict limits configured. The vulnerability has been addressed in version 5.5.6.
Affected Version(s)
fast-xml-parser >= 4.0.0-beta.3, < 5.5.6
