cbcvebase.
CVE-2026-41650
published 2026-05-07

CVE-2026-41650: fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Prior to version 5.7.0, XMLBuilder does not escape the…

PriorityP429medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.24%
15.0th percentile
fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Prior to version 5.7.0, XMLBuilder does not escape the "-->" sequence in comment content or the "]]>" sequence in CDATA sections when building XML from JavaScript objects. This allows XML injection when user-controlled data flows into comments or CDATA elements, leading to XSS, SOAP injection, or data manipulation. This issue has been patched in version 5.7.0.

Affected

20 ranges
VendorProductVersion rangeFixed in
advanced-cluster-securityrhacs-main-rhel8
ansible-automation-platformautomation-portal
apicurioapicurio-registry-ui-rhel8
apicurioapicurio-registry-ui-rhel9
container-native-virtualizationkubevirt-console-plugin
container-native-virtualizationkubevirt-console-plugin-rhel9
mtamta-ui-rhel8
mtamta-ui-rhel9
naturalintelligencefast-xml-builder
naturalintelligencefast-xml-parser< 5.7.05.7.0
naturalintelligencefast-xml-parser>= 0 < 5.7.05.7.0
odf4mcg-core-rhel8
odf4mcg-core-rhel9
odf4ocs-client-console-rhel9
odf4odf-console-rhel9
odf4odf-multicluster-console-rhel9
openshift-gitops-1argocd-rhel8
openshift-gitops-1argocd-rhel9
rhdhrhdh-hub-rhel9
satelliteiop-vulnerability-frontend-rhel9

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
ghsa6.5MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.