Skip to content

Backport CVE-2026-25896 fix to 4.x #792

@yuezk

Description

@yuezk

Hi,

I see the fix has been shipped in 5.3.5. Is there any plan to backport the fix for CVE-2026-25896 to 4.x?

fast-xml-parser is a transitive dependency of adaptive-expressions package provided by Microsoft. But that package's upstream repo has been archved and there is no supported migration path or replacement package published for this dependency chain. So I cannot report issue there to request them to upgrade fast-xml-parser to 5.x. So, I'm open an issue to try my luck here, do we have any plan on this?

Thanks.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions