CVE-2023-26920

NameCVE-2023-26920
Descriptionfast-xml-parser before 4.1.2 allows __proto__ for Prototype Pollution.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
node-webfont (PTS)bookworm11.4.0+dfsg2+~cs35.7.26-7undetermined
trixie11.4.0+dfsg2+~cs35.7.26-13undetermined
forky, sid11.4.0+dfsg2+~cs35.7.26-18undetermined

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
node-webfontsource(unstable)undetermined

Notes

https://gist.github.com/Sudistark/a5a45bd0804d522a1392cb5023aa7ef7
https://github.com/NaturalIntelligence/fast-xml-parser/commit/2b032a4f799c63d83991e4f992f1c68e4dd05804 (4.2.1)
node-webfont provides node-fast-xml-parser

Search for package or bug name: Reporting problems