Skip to content

Security vulnerability: fast-xml-parser #37344

@skhilliard

Description

@skhilliard

It looks like there is a dependency on v5.3.1 of fast-xml-parser:

Image

fast-xml-parser 4.1.3 - 5.3.5
Severity: critical
fast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit) - GHSA-jmr7-xgp7-cmfj
fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names - GHSA-m7jm-9gc2-mpf2

Metadata

Metadata

Assignees

Labels

Azure.Corecustomer-reportedIssues that are reported by GitHub users external to the Azure organization.needs-team-attentionWorkflow: This issue needs attention from Azure service team or SDK teamquestionThe issue doesn't require a change to the product in order to be resolved. Most issues start as that

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions