Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44665

Опубликовано: 13 мая 2026
Источник: redhat
CVSS3: 6.1

Описание

fast-xml-builder builds XML from JSON. Prior to 1.1.7, when an input data has quotes in attribute values but process entities is not enabled, it breaks the attribute value into multiple attributes. This gives the room for an attacker to insert unwanted attributes to the XML/HTML. This vulnerability is fixed in 1.1.7.

A flaw was found in fast-xml-builder, a software component used to create XML documents from JSON data. This vulnerability allows a remote attacker to inject unauthorized attributes into the generated XML or HTML output. By crafting malicious input that includes quotes in attribute values without proper entity processing, an attacker can manipulate the structure of the output. This could lead to unintended information disclosure or alteration of how content is displayed.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-main-rhel8Out of support scope
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Fix deferred
Red Hat Openshift Data Foundation 4odf4/mcg-core-rhel9Out of support scope
Red Hat OpenShift Virtualization 4container-native-virtualization/kubevirt-console-pluginNot affected
Red Hat OpenShift Virtualization 4container-native-virtualization/kubevirt-console-plugin-rhel9Out of support scope
Self-service automation portal 2ansible-automation-platform/automation-portalFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-91
https://bugzilla.redhat.com/show_bug.cgi?id=2477155fast-xml-builder: fast-xml-builder: Attribute injection leading to information disclosure or content manipulation

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
3 месяца назад

fast-xml-builder builds XML from JSON. Prior to 1.1.7, when an input data has quotes in attribute values but process entities is not enabled, it breaks the attribute value into multiple attributes. This gives the room for an attacker to insert unwanted attributes to the XML/HTML. This vulnerability is fixed in 1.1.7.

CVSS3: 6.1
github
3 месяца назад

fast-xml-builder allows attribute values with unwanted quotes to bypass malicious or unwanted attributes

6.1 Medium

CVSS3