CVE-2026-26278 | NaturalIntelligence fast-xml-parser up to 5.3.5 XML Parser xml entity expansion (GHSA-jmr7-xgp7-cmfj)
A vulnerability labeled as problematic has been found in NaturalIntelligence fast-xml-parser up to 5.3.5. The impacted element is an unknown function of the component XML Parser. Such manipulation leads to xml entity expansion.
This vulnerability is listed as CVE-2026-26278. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.