Denial of Service Vulnerability in fast-xml-parser by Natural Intelligence
CVE-2026-33036

7.5HIGH

Key Information:

Vendor
CVE Published:
20 March 2026

What is CVE-2026-33036?

Fast-xml-parser is susceptible to a Denial of Service vulnerability that allows attackers to exploit numeric character references and standard XML entities. This issue arises because the entity count checks only apply to DOCTYPE-defined entities, allowing unregulated numeric and standard entities. By supplying a large number of numeric entity references, attackers can trigger significant memory consumption and CPU load, potentially crashing services even with strict limits configured. The vulnerability has been addressed in version 5.5.6.

Affected Version(s)

fast-xml-parser >= 4.0.0-beta.3, < 5.5.6

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.