CVE-2026-26278
Vulnerability Summary
Timeline
Description
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.1.3 through 5.3.5, the XML parser can be forced to do an unlimited amount of entity expansion. With a very small XML input, it’s possible to make the parser spend seconds or even minutes processing a single request, effectively freezing the application. Version 5.3.6 fixes the issue. As a workaround, avoid using DOCTYPE parsing by `processEntities: false` option.
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 0.86%• Percentile: 57%
Techniques & Countermeasures
- CWE-776•Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.
Affected Systems
- chainguard•dbgate
< 7.0.6-r1
- chainguard•dbgate-fips
< 7.1.0-r0
- chainguard•jitsucom-jitsu-console
< 2.11.0-r15
- chainguard•kibana-8.17
< 8.17.10-r10
- chainguard•kibana-8.17-iamguarded
< 8.17.10-r10
- chainguard•kibana-8.18
all
- chainguard•kibana-8.18-bitnami
all
- chainguard•kibana-8.18-iamguarded
all
- chainguard•kibana-8.19
< 8.19.11-r1
- chainguard•kibana-8.19-bitnami
< 8.19.11-r1
- chainguard•kibana-8.19-iamguarded
< 8.19.11-r1
- chainguard•kibana-9.0
< 9.0.8-r10
- chainguard•kibana-9.0-bitnami
< 9.0.8-r10
- chainguard•kibana-9.0-iamguarded
< 9.0.8-r10
- chainguard•kibana-9.1
< 9.1.10-r5
- chainguard•kibana-9.1-iamguarded
< 9.1.10-r5
- chainguard•kibana-9.2
< 9.2.5-r3
- chainguard•kibana-9.2-iamguarded
< 9.2.5-r3
- chainguard•kibana-9.3
< 9.3.0-r1
- chainguard•kibana-9.3-iamguarded
< 9.3.0-r1
- chainguard•kubeflow-pipelines-frontend
< 2.15.0-r12
- chainguard•langfuse-2-worker
< 2.95.12-r11
- chainguard•langfuse-fips-2-worker
< 2.95.12-r13
- chainguard•librechat
< 0.8.2-r3
- chainguard•nextcloud-server-31
all
- chainguard•prism
< 5.14.3-r7
- chainguard•renovate
< 43.48.3-r0
- chainguard•saf
< 1.6.0-r0
- chainguard•tileserver-gl
< 5.5.0-r5
- chainguard•tileserver-gl-fips
< 5.5.0-r6
- wolfi•jitsucom-jitsu-console
< 2.11.0-r15
- wolfi•kubeflow-pipelines-frontend
< 2.15.0-r12
- wolfi•prism
< 5.14.3-r7
- wolfi•renovate
< 43.48.3-r0
- wolfi•saf
< 1.6.0-r0
- wolfi•tileserver-gl
< 5.5.0-r5
- debian•node-webfont
all | all | all
- naturalintelligence•fast-xml-parser
≥ 5.0.0, < 5.3.6 | ≥ 4.1.3, < 4.5.4 | ≥ 4.1.3, < 5.3.6
- Npm•fast-xml-parser
≥ 4.1.3, < 5.3.6 | ≥ 4.1.3, < 4.5.4 | ≥ 5.0.0, < 5.3.6
References (18)
- https://github.com/NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-jmr7-xgp7-cmfj
- https://github.com/NaturalIntelligence/fast-xml-parser/commit/910dae5be2de2955e968558fadf6e8f74f117a77
- https://github.com/NaturalIntelligence/fast-xml-parser
- https://github.com/NaturalIntelligence/fast-xml-parser/releases/tag/v5.3.6
- https://nvd.nist.gov/vuln/detail/CVE-2026-26278
- https://access.redhat.com/security/cve/CVE-2026-26278
- https://bugzilla.redhat.com/show_bug.cgi?id=2441120
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-26278.json
- https://access.redhat.com/errata/RHSA-2026:7110
- https://access.redhat.com/errata/RHSA-2026:7128
- https://access.redhat.com/errata/RHSA-2026:6174
- https://access.redhat.com/errata/RHSA-2026:6802
- https://access.redhat.com/errata/RHSA-2026:40984
- https://access.redhat.com/errata/RHSA-2026:41941
- https://access.redhat.com/errata/RHSA-2026:41944
- https://access.redhat.com/errata/RHSA-2026:51349
- https://security-tracker.debian.org/tracker/CVE-2026-26278
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26278.json