CVE-2026-73569
Description
fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From 5.9.3 until 5.10.1, src/xmlparser/OrderedObjParser.js processes multiple DOCTYPE declarations within a single XML document and passes each declaration's entities through addInputEntities(). addInputEntities() resets maxTotalExpansions and maxExpandedLength every time it is called, allowing additional DOCTYPE declarations to repeatedly reset the configured entity-expansion limits during one parse operation. A crafted XML document can then cause excessive CPU use, event-loop blocking, memory exhaustion, and process termination. This issue is fixed in version 5.10.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
fast-xml-parsernpm | >= 5.9.3, < 5.10.1 | 5.10.1 |
Affected products
12- osv-coords11 versionspkg:apk/wolfi/jitsucom-jitsu-consolepkg:apk/chainguard/tileserver-glpkg:apk/chainguard/jitsucom-jitsu-consolepkg:apk/chainguard/kibana-9.0pkg:apk/chainguard/langfuse-fips-2-workerpkg:apk/chainguard/thingsboard-tb-js-executor-fipspkg:apk/chainguard/kibana-9.0-bitnamipkg:apk/chainguard/tileserver-gl-fipspkg:apk/chainguard/kibana-9.0-iamguardedpkg:apk/wolfi/tileserver-glpkg:apk/chainguard/langfuse-2-worker
< 2.11.0-r30+ 10 more
- (no CPE)range: < 2.11.0-r30
- (no CPE)range: < 5.6.0-r10
- (no CPE)range: < 2.11.0-r30
- (no CPE)range: < 9.0.8-r34
- (no CPE)range: < 2.95.12-r38
- (no CPE)range: < 4.3.1.3-r3
- (no CPE)range: < 9.0.8-r34
- (no CPE)range: < 5.6.0-r9
- (no CPE)range: < 9.0.8-r34
- (no CPE)range: < 5.6.0-r10
- (no CPE)range: < 2.95.12-r35
- Range: 5.9.3 - 5.10.1
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-8r6m-32jq-jx6qghsaADVISORY
- github.com/NaturalIntelligence/fast-xml-parser/commit/4e546e03987662de5495d050b5fba26bea65383fnvdWEB
- github.com/NaturalIntelligence/fast-xml-parser/releases/tag/v5.10.1nvdWEB
- github.com/NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-8r6m-32jq-jx6qnvdWEB
News mentions
0No linked articles in our index yet.