DEBIAN-CVE-2026-73569

Source
https://security-tracker.debian.org/tracker/CVE-2026-73569
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-73569.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-73569
Upstream
Published
2026-08-13T18:18:19Z
Modified
2026-09-19T22:47:37Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From 5.9.3 until 5.10.1, src/xmlparser/OrderedObjParser.js processes multiple DOCTYPE declarations within a single XML document and passes each declaration's entities through addInputEntities(). addInputEntities() resets maxTotalExpansions and maxExpandedLength every time it is called, allowing additional DOCTYPE declarations to repeatedly reset the configured entity-expansion limits during one parse operation. A crafted XML document can then cause excessive CPU use, event-loop blocking, memory exhaustion, and process termination. This issue is fixed in version 5.10.1.

References

Affected packages

Debian:12 / node-webfont

Package

Name
node-webfont
Purl
pkg:deb/debian/node-webfont?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

11.*
11.4.0+dfsg2+~cs35.7.26-7
11.4.0+dfsg2+~cs35.7.26-8
11.4.0+dfsg2+~cs35.7.26-9
11.4.0+dfsg2+~cs35.7.26-10
11.4.0+dfsg2+~cs35.7.26-11
11.4.0+dfsg2+~cs35.7.26-12
11.4.0+dfsg2+~cs35.7.26-13
11.4.0+dfsg2+~cs35.7.26-14
11.4.0+dfsg2+~cs35.7.26-15
11.4.0+dfsg2+~cs35.7.26-16
11.4.0+dfsg2+~cs35.7.26-18
11.4.0+dfsg2+~cs35.7.26-19
11.4.0+dfsg2+~cs35.7.26-20
11.4.0+dfsg2+~cs35.7.26-21

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-73569.json"

Debian:13 / node-webfont

Package

Name
node-webfont
Purl
pkg:deb/debian/node-webfont?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

11.*
11.4.0+dfsg2+~cs35.7.26-13
11.4.0+dfsg2+~cs35.7.26-14
11.4.0+dfsg2+~cs35.7.26-15
11.4.0+dfsg2+~cs35.7.26-16
11.4.0+dfsg2+~cs35.7.26-18
11.4.0+dfsg2+~cs35.7.26-19
11.4.0+dfsg2+~cs35.7.26-20
11.4.0+dfsg2+~cs35.7.26-21

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-73569.json"

Debian:14 / node-webfont

Package

Name
node-webfont
Purl
pkg:deb/debian/node-webfont?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

11.*
11.4.0+dfsg2+~cs35.7.26-13
11.4.0+dfsg2+~cs35.7.26-14
11.4.0+dfsg2+~cs35.7.26-15
11.4.0+dfsg2+~cs35.7.26-16
11.4.0+dfsg2+~cs35.7.26-18
11.4.0+dfsg2+~cs35.7.26-19
11.4.0+dfsg2+~cs35.7.26-20
11.4.0+dfsg2+~cs35.7.26-21

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-73569.json"