Validate XML, Parse XML, Build XML without C/C++ based libraries
89%
Total Score
100
95
100
100
50
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10621 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. fast-xml-parser is vulnerable to Denial of Service (DoS) in versions 4.0.0 - 5.7.1. | 4.0.0 - 5.7.1 | Medium |
CVE-2026-41650 fast-xml-parser is vulnerable to XML Injection (aka Blind XPath Injection) in versions 0.0.0 - 5.7.0. | 0.0.0 - 5.7.0 | Medium |
CVE-2026-33349 fast-xml-parser is vulnerable to Improper Validation of Specified Quantity in Input in versions 4.0.0-beta.3 - 4.5.5 and 5.0.0 - 5.5.7. | 4.0.0-beta.3 - 4.5.55.0.0 - 5.5.7 | Medium |
CVE-2026-33036 fast-xml-parser is vulnerable to Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') in versions 5.0.0 - 5.5.6 and 4.0.0-beta.3 - 4.5.5. | 4.0.0-beta.3 - 4.5.55.0.0 - 5.5.6 | High |
CVE-2026-27942 fast-xml-parser is vulnerable to Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in versions 5.0.0 - 5.3.8 and 4.0.0-beta.0 - 4.5.4. | 4.0.0-beta.0 - 4.5.45.0.0 - 5.3.8 | Low |
| Dependency | Last Release | Score |
|---|---|---|
strnum Version ^2.3.0 | — | — |
xml-naming Version ^0.1.0 | — | — |
fast-xml-builder Version ^1.2.0 | — | — |
@nodable/entities Version ^2.1.0 | — | — |
path-expression-matcher Version ^1.5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant