PatchSiren

NaturalIntelligence CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH NaturalIntelligence CVE published 2026-08-13

CVE-2026-73569

A crafted XML document can cause excessive CPU use, event-loop blocking, memory exhaustion, and process termination in fast-xml-parser versions between 5.9.3 and 5.10.1. This issue is fixed in version 5.10.1. The vulnerability allows users to process XML from JS objects without C/C++ based libraries or callbacks, leading to potential security risks if not properly mitigated. Defenders and developers shoul [truncated]

MEDIUM NaturalIntelligence CVE published 2026-05-13

CVE-2026-44665

fast-xml-builder prior to version 1.1.7 contains an XML attribute injection vulnerability. When processing JSON input containing quotes within attribute values without entity processing enabled, the library incorrectly splits a single attribute into multiple attributes. This behavior allows injection of unintended attributes into generated XML or HTML output. The vulnerability has a CVSS 3.1 score of 6.1 [truncated]

CRITICAL NaturalIntelligence CVE published 2026-02-20

CVE-2026-25896

A critical vulnerability was discovered in fast-xml-parser, a popular XML parsing library. The vulnerability, tracked as CVE-2026-25896, allows an attacker to inject malicious XML entities, leading to cross-site scripting (XSS) attacks. The vulnerability affects versions 4.1.3 to before 5.3.5 of the library. An attacker can exploit this vulnerability by crafting a malicious XML document that is then parse [truncated]