Skip to content

Commit 56908a7

Browse files
balajacatherinmeta-codesync[bot]
authored andcommitted
Fix CVE-2026-25896: Upgrade deep transitive dependency fast-xml-parser from 4.5.0 to 4.5.4 (#56163)
Summary: Pull Request resolved: #56163 Fix CVE-2026-25896: Upgrade deep transitive dependency fast-xml-parser from 4.5.0 to 4.5.4 ## Summary Upgrading the deep transitive dependency `fast-xml-parser` from 4.5.0 to 4.5.4 in `xplat/js/react-native-github` to fix: - CVE-2026-25896 (Incorrect Regular Expression) Dependency chain (3 levels deep): react-native/tester -> react-native-community/cli-platform-android -> react-native-community/cli-config-android -> fast-xml-parser@^4.4.1 The semver range `^4.4.1` naturally allows 4.5.4, so the version was nudged via temporary resolution and sticks after removal. No permanent resolution needed. Changelog: [General][Security] - Bumped fast-xml-parser from 4.5.0 to 4.5.4 to fix CVE-2026-25896 Reviewed By: huntie Differential Revision: D96997931 fbshipit-source-id: 2ba65763bfb1254c581556559142bfac5450c89d
1 parent 65aee6c commit 56908a7

1 file changed

Lines changed: 3 additions & 3 deletions

File tree

yarn.lock

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -4588,9 +4588,9 @@ fast-uri@^3.0.1:
45884588
integrity sha512-Atfo14OibSv5wAp4VWNsFYE1AchQRTv9cBGWET4pZWHzYshFSS9NQI6I57rdKn9croWVMbYFbLhJ+yJvmZIIHw==
45894589

45904590
fast-xml-parser@^4.4.1:
4591-
version "4.5.0"
4592-
resolved "https://registry.yarnpkg.com/fast-xml-parser/-/fast-xml-parser-4.5.0.tgz#2882b7d01a6825dfdf909638f2de0256351def37"
4593-
integrity sha512-/PlTQCI96+fZMAOLMZK4CWG1ItCbfZ/0jx7UIJFChPNrx7tcEgerUgWbeieCM9MfHInUDyK8DWYZ+YrywDJuTg==
4591+
version "4.5.4"
4592+
resolved "https://registry.yarnpkg.com/fast-xml-parser/-/fast-xml-parser-4.5.4.tgz#64e52ddf1308001893bd225d5b1768840511c797"
4593+
integrity sha512-jE8ugADnYOBsu1uaoayVl1tVKAMNOXyjwvv2U6udEA2ORBhDooJDWoGxTkhd4Qn4yh59JVVt/pKXtjPwx9OguQ==
45944594
dependencies:
45954595
strnum "^1.0.5"
45964596

0 commit comments

Comments
 (0)