| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-33349 | fast-xml-parser: Entity Expansion Limits Bypassed When Set to Zero Due to JavaScript Falsy Evaluation | NaturalIntelligence | fast-xml-parser | Medium | 5.9 | 2026-03-24 19:35:48 | Deep Dive |
| CVE-2026-33036 | fast-xml-parser affected by numeric entity expansion bypassing all entity expansion limits (incomplete fix for CVE-2026-26278) | NaturalIntelligence | fast-xml-parser | High | 7.5 | 2026-03-20 05:17:03 | Deep Dive |
| CVE-2006-10003 | XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack | TODDR | XML::Parser | 超危 | - | 2026-03-19 11:08:04 | Deep Dive |
| CVE-2006-10002 | XML::Parser versions through 2.45 for Perl could overflow the pre-allocated buffer size cause a heap corruption (double free or corruption) and crashes | TODDR | XML::Parser | 高危 | - | 2026-03-19 11:03:47 | Deep Dive |
| CVE-2026-27942 | fast-xml-parser has stack overflow in XMLBuilder with preserveOrder | NaturalIntelligence | fast-xml-parser | - | - | 2026-02-26 01:22:11 | Deep Dive |
| CVE-2026-25896 | fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names | NaturalIntelligence | fast-xml-parser | Critical | 9.3 | 2026-02-20 20:57:48 | Deep Dive |
| CVE-2026-26278 | fast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit) | NaturalIntelligence | fast-xml-parser | High | 7.5 | 2026-02-19 19:40:56 | Deep Dive |
| CVE-2026-25128 | fast-xml-parser has RangeError DoS Numeric Entities Bug | NaturalIntelligence | fast-xml-parser | High | 7.5 | 2026-01-30 15:14:58 | Deep Dive |
| CVE-2024-41818 | ReDOS at currency parsing fast-xml-parser | NaturalIntelligence | fast-xml-parser | High | 7.5 | 2024-07-29 15:56:39 | Deep Dive |
| CVE-2023-34104 | Regex Injection via Doctype Entities | NaturalIntelligence | fast-xml-parser | High | 7.5 | 2023-06-06 17:35:55 | Deep Dive |
| CVE-2021-3666 | Prototype Pollution in fiznool/body-parser-xml | fiznool | fiznool/body-parser-xml | 超危 | - | 2021-09-13 17:56:50 | Deep Dive |