GHSA-8r6m-32jq-jx6q

Suggest an improvement
Source
https://github.com/advisories/GHSA-8r6m-32jq-jx6q
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-8r6m-32jq-jx6q/GHSA-8r6m-32jq-jx6q.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-8r6m-32jq-jx6q
Aliases
Downstream
CGA (25)
Published
2026-07-21T22:06:36Z
Modified
2026-09-10T03:51:11Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits
Details

Impact

fast-xml-parser processes multiple "DOCTYPE" declarations within a single XML document. Each declaration passes its entities to @nodable/entities through addInputEntities().

addInputEntities() resets the entity expansion counters every time it is called. An attacker can therefore insert additional DOCTYPE declarations to repeatedly reset maxTotalExpansions and maxExpandedLength during one parse operation.

This allows a crafted XML document to exceed the configured entity-expansion limits and can cause excessive CPU use, event-loop blocking, memory exhaustion, and process termination.

Workarounds

  • Manually check if multiple DOCTYPEs are not present in input contents
  • Update to v5.10.1
  • Keep processEntity flag off
Database specific
{
    "cwe_ids":  [
        "CWE-776"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-21T22:06:36Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / fast-xml-parser

Package

Name
fast-xml-parser
View open source insights on deps.dev
Purl
pkg:npm/fast-xml-parser

Affected ranges

Type
SEMVER
Events
Introduced
5.9.3
Fixed
5.10.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-8r6m-32jq-jx6q/GHSA-8r6m-32jq-jx6q.json"