Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
716894
AlmaLinux
5103
Alpaquita
10949
Alpine
4284
Android
3402
Azure Linux
12016
BellSoft Hardened Containers
521
Bitnami
8145
Chainguard
7203
CleanStart
1506
CRAN
14
crates.io
2489
Debian
58662
Echo
5608
GHC
3
GIT
81700
GitHub Actions
54
Go
7308
Hackage
32
Hex
142
Julia
958
Linux
15361
Mageia
6002
Maven
6602
MinimOS
75201
npm
220916
NuGet
1735
opam
18
openEuler
7054
openSUSE
13132
OSS-Fuzz
3937
Packagist
6554
Pub
11
PyPI
20279
Red Hat
20783
Rocky Linux
3496
Root
16026
RubyGems
2000
SUSE
20931
SwiftURL
58
TuxCare
5651
Ubuntu
56306
VSCode
20
Wolfi
4722
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-gh4j-gqv2-49f6
npm/fast-xml-parser
fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters
22 Apr
Fix available
Severity - 6.1 (Medium)
GHSA-jp2q-39xq-3w4g
npm/fast-xml-parser
Entity Expansion Limits Bypassed When Set to Zero Due to JavaScript Falsy Evaluation in fast-xml-parser
19 Mar
Fix available
Severity - 5.9 (Medium)
GHSA-8gc5-j5rx-235r
npm/fast-xml-parser
fast-xml-parser affected by numeric entity expansion bypassing all entity expansion limits (incomplete fix for CVE-2026-26278)
17 Mar
Fix available
Severity - 7.5 (High)
GHSA-fj3w-jwp8-x2g3
npm/fast-xml-parser
fast-xml-parser has stack overflow in XMLBuilder with preserveOrder
26 Feb
Fix available
Severity - 2.7 (Low)
GHSA-m7jm-9gc2-mpf2
npm/fast-xml-parser
fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names
20 Feb
Fix available
Severity - 9.3 (Critical)
GHSA-jmr7-xgp7-cmfj
npm/fast-xml-parser
fast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit)
17 Feb
Fix available
Severity - 7.5 (High)
GHSA-37qj-frw5-hhjh
npm/fast-xml-parser
fast-xml-parser has RangeError DoS Numeric Entities Bug
30 Jan
Fix available
Severity - 7.5 (High)
GHSA-mpg4-rc92-vx8v
npm/fast-xml-parser
fast-xml-parser vulnerable to ReDOS at currency parsing
29 Jul 2024
Fix available
Severity - 8.7 (High)
GHSA-gpv5-7x3g-ghjv
npm/fast-xml-parser
fast-xml-parser regex vulnerability patch could be improved from a safety perspective
15 Jun 2023
Fix available
GHSA-x3cc-x39p-42qx
npm/fast-xml-parser
fast-xml-parser vulnerable to Prototype Pollution through tag or attribute name
13 Jun 2023
Fix available
Severity - 6.5 (Medium)
GHSA-6w63-h3fj-q4vw
npm/fast-xml-parser
fast-xml-parser vulnerable to Regex Injection via Doctype Entities
06 Jun 2023
Fix available
Severity - 7.5 (High)
npm - OSV