Uncaught Exception in fast-xml-parser - CVE-2026-25128

 

Uncaught Exception in fast-xml-parser - CVE-2026-25128

Published: January 30, 2026 / Updated: January 31, 2026


Vulnerability identifier: #VU122150
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-25128
CWE-ID: CWE-248
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to the RangeError issue in the numeric entity. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Affected software

fast-xml-parser
Guardium Data Security Center (GDSC)
watsonx Code Assistant On Prem
Maximo Application Suite Ai Service
Planning Analytics Local
IBM DataPower Gateway
IBM App Connect Enterprise
OpenShift Data Foundation (formerly OpenShift Container Storage)
App Connect Enterprise Certified Container

How to mitigate CVE-2026-25128

Install updates from vendor's website.

fast-xml-parser - update to 5.3.4
Planning Analytics Local - update to 2.1.19
Guardium Data Security Center (GDSC) - update to 3.8.8
watsonx Code Assistant On Prem - update to 5.3.1
Maximo Application Suite Ai Service - update to 9.1.13
IBM DataPower Gateway - addressed in versions 10.5.0.21, 10.6.0.9, 11.0.0.0
IBM App Connect Enterprise - addressed in versions 12.0.12.24, 13.0.6.2
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.18.24, 4.19.20
App Connect Enterprise Certified Container - addressed in versions 12.0.21, 12.21.0

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins