CVE-2026-33036 | NaturalIntelligence fast-xml-parser up to 5.5.5 replaceEntitiesValue xml entity expansion (Nessus ID 303270)
A vulnerability identified as problematic has been detected in NaturalIntelligence fast-xml-parser up to 5.5.5. Affected is the function replaceEntitiesValue. Performing a manipulation results in xml entity expansion.
This vulnerability is identified as CVE-2026-33036. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.