CVE-2026-25896
fast-xml-parser DOCTYPE entity name wildcard bypass allows XSS.
Halo Surface Signal: 3 out of 5 — possibly public-facing.
The fast-xml-parser library is vulnerable to a cross-site scripting (XSS) flaw that can be exploited by manipulating DOCTYPE entity names. An attacker could craft malicious XML to bypass entity encoding, potentially leading to script execution if the parsed output is rendered without sanitization. This issue affects us