Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44664

Опубликовано: 13 мая 2026
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

fast-xml-builder builds XML from JSON. In 1.1.5, the fix for CVE-2026-41650 in fast-xml-parser sanitizes -- sequences in XML comment content using .replace(/--/g, '- -'). This skip the values containing three consecutive dashes (e.g., --->...), allowing an attacker to break out of an XML comment and inject arbitrary XML/HTML content. This vulnerability is fixed in 1.1.6.

A flaw was found in fast-xml-builder. The software, which builds XML from JSON, incorrectly sanitizes XML comment content. This allows a remote attacker to bypass the sanitization by using three consecutive dashes, enabling them to break out of an XML comment and inject arbitrary XML or HTML content. This could lead to content manipulation or other impacts depending on how the generated XML is processed.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-main-rhel8Not affected
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Not affected
Red Hat Openshift Data Foundation 4odf4/mcg-core-rhel9Not affected
Red Hat OpenShift Virtualization 4container-native-virtualization/kubevirt-console-pluginNot affected
Red Hat OpenShift Virtualization 4container-native-virtualization/kubevirt-console-plugin-rhel9Not affected
Self-service automation portal 2ansible-automation-platform/automation-portalFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-91
https://bugzilla.redhat.com/show_bug.cgi?id=2477164fast-xml-builder: fast-xml-builder: Arbitrary XML/HTML injection via insufficient sanitization of XML comments

EPSS

Процентиль: 9%
0.00194
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
3 месяца назад

fast-xml-builder builds XML from JSON. In 1.1.5, the fix for CVE-2026-41650 in fast-xml-parser sanitizes -- sequences in XML comment content using .replace(/--/g, '- -'). This skip the values containing three consecutive dashes (e.g., --->...), allowing an attacker to break out of an XML comment and inject arbitrary XML/HTML content. This vulnerability is fixed in 1.1.6.

CVSS3: 6.1
github
3 месяца назад

fast-xml-builder Comment Value regex can be bypassed

EPSS

Процентиль: 9%
0.00194
Низкий

6.1 Medium

CVSS3