Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2192872
AlmaLinux
5906
Alpaquita
15522
Alpine
4594
Android
3674
Azure Linux
17170
BellSoft Hardened Containers
744
Bitnami
9227
Chainguard
1022425
CleanStart
3529
CRAN
14
crates.io
2730
Debian
67904
Echo
6685
GHC
3
GIT
107255
GitHub Actions
55
Go
9202
Hackage
32
Hex
358
Julia
1713
Linux
29602
Mageia
6222
Maven
7011
MinimOS
143505
npm
228724
NuGet
1867
opam
29
openEuler
8800
openSUSE
14377
OSS-Fuzz
4006
Packagist
7091
Pub
11
PyPI
25150
Red Hat
23316
Rocky Linux
4279
Root
19521
RubyGems
5325
SUSE
23077
SwiftURL
60
TuxCare
9421
Ubuntu
64999
VSCode
21
Wolfi
287716
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-8r6m-32jq-jx6q
npm/fast-xml-parser
fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits
21 Jul
Fix available
Severity - 8.7 (High)
GHSA-gh4j-gqv2-49f6
npm/fast-xml-parser
fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters
22 Apr
Fix available
Severity - 6.1 (Medium)
GHSA-jp2q-39xq-3w4g
npm/fast-xml-parser
Entity Expansion Limits Bypassed When Set to Zero Due to JavaScript Falsy Evaluation in fast-xml-parser
19 Mar
Fix available
Severity - 5.9 (Medium)
GHSA-8gc5-j5rx-235r
npm/fast-xml-parser
fast-xml-parser affected by numeric entity expansion bypassing all entity expansion limits (incomplete fix for CVE-2026-26278)
17 Mar
Fix available
Severity - 7.5 (High)
GHSA-fj3w-jwp8-x2g3
npm/fast-xml-parser
fast-xml-parser has stack overflow in XMLBuilder with preserveOrder
26 Feb
Fix available
Severity - 2.7 (Low)
GHSA-m7jm-9gc2-mpf2
npm/fast-xml-parser
fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names
20 Feb
Fix available
Severity - 9.3 (Critical)
GHSA-jmr7-xgp7-cmfj
npm/fast-xml-parser
fast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit)
17 Feb
Fix available
Severity - 7.5 (High)
GHSA-37qj-frw5-hhjh
npm/fast-xml-parser
fast-xml-parser has RangeError DoS Numeric Entities Bug
30 Jan
Fix available
Severity - 7.5 (High)
GHSA-mpg4-rc92-vx8v
npm/fast-xml-parser
fast-xml-parser vulnerable to ReDOS at currency parsing
29 Jul 2024
Fix available
Severity - 8.7 (High)
GHSA-gpv5-7x3g-ghjv
npm/fast-xml-parser
fast-xml-parser regex vulnerability patch could be improved from a safety perspective
15 Jun 2023
Fix available
GHSA-x3cc-x39p-42qx
npm/fast-xml-parser
fast-xml-parser vulnerable to Prototype Pollution through tag or attribute name
13 Jun 2023
Fix available
Severity - 6.5 (Medium)
GHSA-6w63-h3fj-q4vw
npm/fast-xml-parser
fast-xml-parser vulnerable to Regex Injection via Doctype Entities
06 Jun 2023
Fix available
Severity - 7.5 (High)
npm - OSV