Junglewise Threat Intelligence

CVE-2026-33349: fast-xml-parser entity expansion bypass via falsy zero check

CVE-2026-33349 · Severity: low · CVSS 3.1 · Published 2026-03-19

Executive brief

fast-xml-parser is a widely-used Node.js library for parsing XML files. When developers configure the parser to block all entities by setting strict limits to zero, a JavaScript programming error causes those limits to be silently ignored. An attacker supplying malicious XML with thousands of entity definitions can exhaust server memory, crashing applications and disrupting service.

Technical details

The vulnerability is a logic error in DocTypeReader.js where entity expansion limits (maxEntityCount and maxEntitySize) are checked using truthy evaluation (&&) instead of explicit type checks. Since 0 is falsy in JavaScript, conditions like "if (this.options.maxEntityCount && entityCount >= maxEntityCount)" evaluate to false when the limit is 0, completely bypassing the check. An attacker can supply XML with a DOCTYPE containing thousands of large entity definitions; the parser will parse them without restriction, leading to memory exhaustion and denial of service. The vulnerability affects versions 4.0.0-beta.3 through 5.5.6; it is fixed in versions 4.5.5 and 5.5.7 by replacing truthy checks with explicit typeof checks. Default configurations are not vulnerable as they use non-zero defaults (maxEntityCount: 100, maxEntitySize: 10000).

Affected products

  • NaturalIntelligence fast-xml-parser 4.0.0-beta.3 through 5.5.6 (patched in 4.5.5, 5.5.7)

Timeline

  • 2026-03-19: disclosed
  • 2026-03-19: patched: Versions 4.5.5 and 5.5.7 include the fix

References