Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-73569

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From 5.9.3 until 5.10.1, src/xmlparser/OrderedObjParser.js processes multiple DOCTYPE declarations within a single XML document and passes each declaration's entities through addInputEntities(). addInputEntities() resets maxTotalExpansions and maxExpandedLength every time it is called, allowing additional DOCTYPE declarations to repeatedly reset the configured entity-expansion limits during one parse operation. A crafted XML document can then cause excessive CPU use, event-loop blocking, memory exhaustion, and process termination. This issue is fixed in version 5.10.1.

A flaw was found in fast-xml-parser. A remote attacker could exploit this by submitting a specially crafted XML document containing multiple DOCTYPE declarations. These repeated declarations can reset internal entity expansion limits during parsing. This can lead to excessive CPU usage, event-loop blocking, and memory exhaustion, ultimately resulting in a Denial of Service (DoS) for the application processing the XML.

Отчет

This is an Important denial of service vulnerability affecting Red Hat products that process untrusted XML input using the fast-xml-parser library versions 5.9.3 through 5.10.0. A remote attacker could provide a specially crafted XML document with multiple DOCTYPE declarations, leading to excessive CPU usage, memory exhaustion, and potential service disruption.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Applications 8mta/mta-ui-rhel9Affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-main-rhel8Not affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-main-rhel9Not affected
Red Hat build of Apicurio Registry 3apicurio/apicurio-registry-ui-rhel8Not affected
Red Hat Developer Hubrhdh/red-hat-developer-hub-backstage-plugin-lightspeedNot affected
Red Hat Developer Hubrhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backendNot affected
Red Hat Developer Hubrhdh/red-hat-developer-hub-backstage-plugin-orchestratorNot affected
Red Hat Developer Hubrhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backendNot affected
Red Hat Developer Hubrhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend-module-lokiNot affected
Red Hat Developer Hubrhdh/red-hat-developer-hub-backstage-plugin-orchestrator-form-widgetsNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-776
https://bugzilla.redhat.com/show_bug.cgi?id=2515526fast-xml-parser: fast-xml-parser: Denial of Service via repeated DOCTYPE declarations

EPSS

Процентиль: 30%
0.00372
Низкий

7.5 High

CVSS3

Связанные уязвимости

ubuntu
16 дней назад

fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From 5.9.3 until 5.10.1, src/xmlparser/OrderedObjParser.js processes multiple DOCTYPE declarations within a single XML document and passes each declaration's entities through addInputEntities(). addInputEntities() resets maxTotalExpansions and maxExpandedLength every time it is called, allowing additional DOCTYPE declarations to repeatedly reset the configured entity-expansion limits during one parse operation. A crafted XML document can then cause excessive CPU use, event-loop blocking, memory exhaustion, and process termination. This issue is fixed in version 5.10.1.

nvd
16 дней назад

fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From 5.9.3 until 5.10.1, src/xmlparser/OrderedObjParser.js processes multiple DOCTYPE declarations within a single XML document and passes each declaration's entities through addInputEntities(). addInputEntities() resets maxTotalExpansions and maxExpandedLength every time it is called, allowing additional DOCTYPE declarations to repeatedly reset the configured entity-expansion limits during one parse operation. A crafted XML document can then cause excessive CPU use, event-loop blocking, memory exhaustion, and process termination. This issue is fixed in version 5.10.1.

debian
16 дней назад

fast-xml-parser allows users to process XML from JS object without C/C ...

github
около 1 месяца назад

fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits

EPSS

Процентиль: 30%
0.00372
Низкий

7.5 High

CVSS3

Уязвимость CVE-2026-73569