fast-xml-parser
NPM Package
Vulnerability Check
Validate XML, Parse XML, Build XML without C/C++ based libraries
fast-xml-parser
Advisory Breakdown
Severity Rating
Critical11 advisories
Critical
Weekly downloads
87,606,262
Total advisories
11
Latest version
5.8.0
License
MIT
Known advisories
OSV records for the npm ecosystem
fast-xml-parser has RangeError DoS Numeric Entities Bug
fast-xml-parser vulnerable to Regex Injection via Doctype Entities
fast-xml-parser affected by numeric entity expansion bypassing all entity expansion limits (incomplete fix for CVE-2026-26278)
fast-xml-parser has stack overflow in XMLBuilder with preserveOrder
fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters
fast-xml-parser regex vulnerability patch could be improved from a safety perspective
fast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit)
Entity Expansion Limits Bypassed When Set to Zero Due to JavaScript Falsy Evaluation in fast-xml-parser
fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names
fast-xml-parser vulnerable to ReDOS at currency parsing
fast-xml-parser vulnerable to Prototype Pollution through tag or attribute name
Checked Jun 14, 2026, 10:37 PM from npm and OSV.dev
Package metadata
From the npm registry
- Package name
- fast-xml-parser
- Ecosystem
- npm
- Latest version
- 5.8.0
- License
- MIT
- Weekly downloads
- 87,606,262
- Repository
- Open repository
Remediation boundary
What RequestGuard does — and doesn't — cover
RequestGuard does not fix npm package vulnerabilities. Dependency remediation happens through package updates, patches, lockfile changes, and maintainer guidance. RequestGuard can help mitigate runtime abuse around exposed web and API flows while remediation is handled separately.
Data from npm registry and OSV.dev · Checked 6/14/2026, 10:37:48 PM