cbcvebase.
CVE-2023-26920
published 2023-12-12

CVE-2023-26920: fast-xml-parser before 4.1.2 allows __proto__ for Prototype Pollution.

PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.15%
63.6th percentile
fast-xml-parser before 4.1.2 allows __proto__ for Prototype Pollution.

Affected

4 ranges
VendorProductVersion rangeFixed in
debiannode-webfont
naturalintelligencefast-xml-parser>= 0 < 4.1.24.1.2
naturalintelligencefast-xml-parser>= 0 < 5.7.05.7.0
naturalintelligencefast_xml_parser< 4.1.24.1.2

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
ghsa6.5MEDIUM
osv6.5MEDIUM
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.