Vulnerabilities/

Entity Expansion Limits Bypassed When Set to Zero Due to JavaScript Falsy Evaluation in fast-xml-parser

Severity:
Medium

Description

The DocTypeReader in fast-xml-parser uses JavaScript truthy checks to evaluate maxEntityCount and maxEntitySize configuration limits.

Recommendation

Update the fast-xml-parser package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
fast-xml-parser
Anything's wrong? Let us know Last updated on March 25, 2026