🛡️ CVE-2026-26278 — fast-xml-parser

🟠 CVSS 8.0 — High ⚠️ Exploit Public CWE-776 OSV
8.0
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

fast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit)

Summary

The XML parser can be forced to do an unlimited amount of entity expansion. With a very small XML input, it’s possible to make the parser spend seconds or even minutes processing a single request, effectively freezing the application.

Details

There is a check in DocTypeReader.js that tries to prevent entity expansion attacks by rejecting entities that reference other entities (it looks for & inside entity values). This does stop classic “Billion Laughs” payloads.

However, it doesn’t stop a much simpler variant.

If you define one large entity that contains only raw text (no & characters) and then reference it many times, the parser will happily expand it every time. There is no limit on how large the expanded result can become, or how many replacements are allowed.

The problem is in replaceEntitiesValue() inside OrderedObjParser.js. It repeatedly runs val.replace() in a loop, without any checks on total output size or execution cost. As the entity grows or the number of references increases, parsing time explodes.

Relevant code:

DocTypeReader.js (lines 28–33): entity registration only checks for &

OrderedObjParser.js (lines 439–458): entity replacement loop with no limits

PoC

```js

const { XMLParser } = require('fast-xml-parser');

const entity = 'A'.repeat(1000);

const refs = '&big;'.repeat(100);

const xml = <!DOCTYPE foo [<!ENTITY big "${entity}">]><root>${refs}</root>;

console.time('parse');

new XMLParser().parse(xml); // ~4–8 seconds for ~1.3 KB of XML

console.timeEnd('parse');

// 5,000 chars × 100 refs takes 200+ seconds

// 50,000 chars × 1,000 refs will hang indefinitely

```

Impact

This is a straightforward denial-of-service issue.

Any service that parses user-supplied XML using the default configuration is vulnerable. Since Node.js runs on a single thread, the moment the parser starts expanding entities, the event loop is blocked. While this is happening, the server can’t handle any other requests.

In testing, a payload of only a few kilobytes was enough to make a simple HTTP server completely unresponsive for several minutes, with all other requests timing out.

Workaround

Avoid using DOCTYPE parsing by processEntities: false option.

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality none, integrity none, availability high.

Weakness class

CVE-2026-26278 is classified as CWE-776: XML Entity Expansion. Nested entity definitions expand enormously when parsed, consuming memory and CPU.

Affected software

CVE-2026-26278 is recorded against 1 package.

  • fast-xml-parser

Timeline and source

Published on 17 February 2026 and last revised on 7 August 2026. A public exploit is known to exist, which raises the urgency of patching considerably. A vendor advisory or fix has been published. Record sourced from OSV.

References

github.com (Web)
nvd.nist.gov (Advisory)
github.com (Web)
github.com (Package)
github.com (Web)

CVE-2026-26278 on other distributions

Each distribution ships its own build and its own fixed version. Pick the one you run:

Details

Severity HIGH
CVSS Score 8.0
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE CWE-776
Public Exploit ⚠️ Yes
Source OSV
Published 2026-02-17
Updated 2026-08-12
Modified 2026-08-07

Affected Packages

Software From version Fixed in
fast-xml-parser

Exploit Protection

Are you running fast-xml-parser?

CVE-2026-26278 carries CVSS 8.0 High rating and a public exploit already exists. BotEraser checks your installation against this and other known CVE records, and blocks IPs associated with exploit activity.

Check My Site For CVE-2026-26278 →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.