CVE-2026-26278

Aliases:GHSA-jmr7-xgp7-cmfjDEBIAN-CVE-2026-26278CGA-5639-crfc-phjjCGA-99x8-hx2v-cvjvCGA-9qqr-hrcw-h426CGA-g5wp-ccfc-g46vCGA-h6gh-pvh3-vh5qCGA-h82x-f99v-hr4fCGA-hmj5-7j3m-pmr6CGA-mjhp-vcfv-pr84CGA-pg2j-f6qf-x8mwCGA-pv5r-jg5j-g76jCGA-22c9-r66g-v2q3CGA-2f3x-9f5w-pchcCGA-2r8r-cgq6-8w45CGA-2wfw-7v2q-9v3wCGA-32x5-xhc4-hqqjCGA-46hh-92r6-vhfwCGA-4fwf-c92h-p3m8CGA-4gwq-p89c-prwpCGA-4qh7-4r83-q62rCGA-59q7-89r4-697xCGA-5hrq-3qqw-67vvCGA-5hx8-gw37-x4p2CGA-69cm-h6vg-42v3CGA-6jw8-7gpq-884jCGA-7578-5c66-63qjCGA-77m2-3hgp-5mfvCGA-78r6-hh3c-rvvrCGA-8f3f-whrm-hhg2CGA-93r6-6mc7-mp5wCGA-96rj-48hq-8x7hCGA-9f4f-h6pg-793qCGA-9fx2-2f5g-7wwrCGA-9g6g-52q6-3fgwCGA-c23m-r8ff-7h44CGA-c72r-86c8-rf8pCGA-f545-mpj6-q59gCGA-f5f3-r73w-c965CGA-fhq5-8rwj-qw22CGA-fjmp-7rwf-3mq3CGA-fx35-pmx2-7mc8CGA-g5g2-qp5r-jvxjCGA-hh5f-fmhh-3c4pCGA-j9mf-cwqr-cf9qCGA-jg85-23vh-6r59CGA-jjwp-x639-x4hhCGA-jp4f-qqxf-fh2wCGA-m23f-rgq9-6pg8CGA-m398-qm8f-jpvfCGA-m78g-232g-rmjrCGA-mjxg-2h34-wcqqCGA-mvj2-v982-qv8qCGA-p96w-v67j-r444CGA-ph5f-fprg-hpfpCGA-pqr4-7v4v-9c7wCGA-pv6h-qh3p-m8vqCGA-pvjm-7wg5-5hpjCGA-q3ch-q8cc-wwp3CGA-qfc5-hqm2-q42cCGA-qw2f-9j9j-rwv5CGA-qwg9-pgjm-9vjrCGA-r6c3-46fq-36w8CGA-rjw6-8mh4-5gc8CGA-v2wp-hcv4-5m9mCGA-v44w-6998-2h2vCGA-vg77-26rh-4g58CGA-vh3q-6g44-jfvvCGA-vpm9-gfp3-wxj4CGA-w5wf-42cf-p6c3CGA-wcg4-p8gw-wfx8CGA-xf9p-8r48-g755CGA-xhpq-5p6v-rp98CGA-xq3v-8v8f-32g3CGA-xwp9-hxm2-5fcm
Modified
Published: 19 Feb 2026, 19:40
Last modified:10 Sept 2026, 12:05

Vulnerability Summary

Overall Risk (default)
medium
40/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
0.86% LOW
1% probability +0.83%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

19 Feb 2026, 19:40
Published
Vulnerability first disclosed
10 Sept 2026, 12:05
Last Modified
Vulnerability information updated

Description

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.1.3 through 5.3.5, the XML parser can be forced to do an unlimited amount of entity expansion. With a very small XML input, it’s possible to make the parser spend seconds or even minutes processing a single request, effectively freezing the application. Version 5.3.6 fixes the issue. As a workaround, avoid using DOCTYPE parsing by `processEntities: false` option.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.86% Percentile: 57%

Techniques & Countermeasures

  • CWE-776Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

    The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.

Affected Systems

  • chainguarddbgate

    < 7.0.6-r1

  • chainguarddbgate-fips

    < 7.1.0-r0

  • chainguardjitsucom-jitsu-console

    < 2.11.0-r15

  • chainguardkibana-8.17

    < 8.17.10-r10

  • chainguardkibana-8.17-iamguarded

    < 8.17.10-r10

  • chainguardkibana-8.18

    all

  • chainguardkibana-8.18-bitnami

    all

  • chainguardkibana-8.18-iamguarded

    all

  • chainguardkibana-8.19

    < 8.19.11-r1

  • chainguardkibana-8.19-bitnami

    < 8.19.11-r1

  • chainguardkibana-8.19-iamguarded

    < 8.19.11-r1

  • chainguardkibana-9.0

    < 9.0.8-r10

  • chainguardkibana-9.0-bitnami

    < 9.0.8-r10

  • chainguardkibana-9.0-iamguarded

    < 9.0.8-r10

  • chainguardkibana-9.1

    < 9.1.10-r5

  • chainguardkibana-9.1-iamguarded

    < 9.1.10-r5

  • chainguardkibana-9.2

    < 9.2.5-r3

  • chainguardkibana-9.2-iamguarded

    < 9.2.5-r3

  • chainguardkibana-9.3

    < 9.3.0-r1

  • chainguardkibana-9.3-iamguarded

    < 9.3.0-r1

  • chainguardkubeflow-pipelines-frontend

    < 2.15.0-r12

  • chainguardlangfuse-2-worker

    < 2.95.12-r11

  • chainguardlangfuse-fips-2-worker

    < 2.95.12-r13

  • chainguardlibrechat

    < 0.8.2-r3

  • chainguardnextcloud-server-31

    all

  • chainguardprism

    < 5.14.3-r7

  • chainguardrenovate

    < 43.48.3-r0

  • chainguardsaf

    < 1.6.0-r0

  • chainguardtileserver-gl

    < 5.5.0-r5

  • chainguardtileserver-gl-fips

    < 5.5.0-r6

  • wolfijitsucom-jitsu-console

    < 2.11.0-r15

  • wolfikubeflow-pipelines-frontend

    < 2.15.0-r12

  • wolfiprism

    < 5.14.3-r7

  • wolfirenovate

    < 43.48.3-r0

  • wolfisaf

    < 1.6.0-r0

  • wolfitileserver-gl

    < 5.5.0-r5

  • debiannode-webfont

    all | all | all

  • naturalintelligencefast-xml-parser

    ≥ 5.0.0, < 5.3.6 | ≥ 4.1.3, < 4.5.4 | ≥ 4.1.3, < 5.3.6

  • Npmfast-xml-parser

    ≥ 4.1.3, < 5.3.6 | ≥ 4.1.3, < 4.5.4 | ≥ 5.0.0, < 5.3.6

References (18)