CVE detail
CVE-2026-26278
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.1.3 through 5.3.5, the XML parser can be forced to do an unlimited amount of entity expansion. With a very small XML input, it’s possible to make the parser spend seconds or even minutes processing a single request, effectively freezing the application. Version 5.3.6 fixes the issue. As a workaround, avoid using DOCTYPE parsing by `processEntities: false` option.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 26.4 · diversity 13.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
13 source links · newest first
- https://access.redhat.com/errata/RHSA-2026:41944access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 19, 2026, 8:25 PM - https://access.redhat.com/errata/RHSA-2026:41941access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 19, 2026, 8:25 PM - https://access.redhat.com/errata/RHSA-2026:40984access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 19, 2026, 8:25 PM - https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-26278.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comFeb 19, 2026, 8:25 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2441120bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comFeb 19, 2026, 8:25 PM - https://access.redhat.com/security/cve/CVE-2026-26278access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 19, 2026, 8:25 PM - https://access.redhat.com/errata/RHSA-2026:7128access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 19, 2026, 8:25 PM - https://access.redhat.com/errata/RHSA-2026:7110access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 19, 2026, 8:25 PM - https://access.redhat.com/errata/RHSA-2026:6802access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 19, 2026, 8:25 PM - https://access.redhat.com/errata/RHSA-2026:6174access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 19, 2026, 8:25 PM - https://github.com/NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-jmr7-xgp7-cmfjgithub.com
No excerpt available.
Exploitgithub.comFeb 19, 2026, 8:25 PM No excerpt available.
Exploitgithub.comFeb 19, 2026, 8:25 PMNo excerpt available.
Exploitgithub.comFeb 19, 2026, 8:25 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-33036CVSS 7.5 · High
fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Versions 4.0.0-beta.3 through 5.5.5 contain a bypass vulnerability where num…
- CVE-2026-14865CVSS 5.3 · Medium
In Progress® Telerik® UI for AJAX prior to v2026.2.708, the internal LayoutBuilder control processes client-state XML without disabling DTD processing, allowing unauthenticated de…
- CVE-2026-14979CVSS 5.3 · Medium
IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ) Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 DOOR…
- CVE-2026-45304CVSS 8.7 · High
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Yaml\Parser resolv…
- CVE-2026-45133CVSS 8.2 · High
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, when the parser is exposed to attack…
- CVE-2026-44018CVSS 5.5 · Medium
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91.0, the METS-GBS backend's XML…