CVE-2026-33349 - Vulnerability Analysis
MediumCVSS: 5.9Last Updated: March 26, 2026
fast-xml-parser - Denial of Service
Published: March 24, 2026Updated: March 26, 2026PoC AvailableRemote Exploitable
Overview
fast-xml-parser >= 4.0.0-beta.3 and < 5.5.7 contains a denial of service caused by improper JavaScript truthy checks in DocTypeReader for maxEntityCount and maxEntitySize, letting attackers trigger unbounded entity expansion, exploit requires attacker to supply crafted XML input.
Severity & Score
Severity: Medium
CVSS Score: 5.9
Impact
Attackers can cause memory exhaustion and denial of service by triggering unbounded entity expansion.
Mitigation
Upgrade to version 5.5.7 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-33349
- Severity
- Medium
- CVSS Score
- 5.9
- Type
- xml_external_entity_injection
- Status
- confirmed
CWE
- CWE-1284
CVSS Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H