Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
NaturalIntelligence fast-xml-parser — fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N C L H N 9.3 .0046 38.4 —
AFFECTED
Product Versions Fixed
fast-xml-parser >= 5.0.0, < 5.3.5 – —
TIMELINE
Feb 6 Reserved by GitHub_M
Feb 20 Published (CNA: GitHub_M)
Aug 18 EXPLOIT PUBLISHED — CVE-2026-25896 (NaturalIntelligence fast-xml-parser). Public exploit reference added.
Description
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow built-in XML entities (<, >, &, ", ') with arbitrary values. This bypasses entity encoding and leads to XSS when parsed output is rendered. This vulnerability is fixed in 5.3.5.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| February 6, 2026 | Reserved | Reserved by GitHub_M |
| February 20, 2026 | Published | Published (CNA: GitHub_M) |
| August 18, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-25896 (NaturalIntelligence fast-xml-parser). Public exploit reference added. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| NaturalIntelligence | fast-xml-parser | — | >= 5.0.0, < 5.3.5 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-25896 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.