CVE-2026-44665
Last modified
CVE-2026-44665 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. fast-xml-builder builds XML from JSON. Prior to 1.1.7, when an input data has quotes in attribute values but process entities is not enabled, it breaks the attribute value into multiple attributes. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
fast-xml-builder builds XML from JSON. Prior to 1.1.7, when an input data has quotes in attribute values but process entities is not enabled, it breaks the attribute value into multiple attributes. This gives the room for an attacker to insert unwanted attributes to the XML/HTML. This vulnerability is fixed in 1.1.7.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-44665?
How severe is CVE-2026-44665?
How do I fix CVE-2026-44665?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-4466A vulnerability has been found in Comfast CF-AC100 2.6.0.8. …4.7
- CVE-2026-44660UltraJSON is a fast JSON encoder and decoder written in pure…7.5
- CVE-2026-44661python-utcp is the python implementation of UTCP. Prior to 1…4.7
- CVE-2026-44662rust-openssl provides OpenSSL bindings for the Rust programm…5.1
- CVE-2026-44663OpenEXR is the reference implementation and specification fo…7.1
- CVE-2026-44664fast-xml-builder builds XML from JSON. In 1.1.5, the fix for…6.1
- CVE-2026-44666HRConvert2 is a self-hosted, drag-and-drop & nosql file conv…9.3
- CVE-2026-44667FACTION is a PenTesting Report Generation and Collaboration …8.7
- CVE-2026-44668FACTION is a PenTesting Report Generation and Collaboration …9.8
- CVE-2026-44669FACTION is a PenTesting Report Generation and Collaboration …8.7
- CVE-2026-4467A vulnerability was found in Comfast CF-AC100 2.6.0.8. This …4.7
- CVE-2026-44670SiYuan is an open-source personal knowledge management syste…9.4
Are you affected by CVE-2026-44665?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
