Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-71497

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 4.7

Описание

jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectly handle a malformed tag name ending in a control character, causing the tag to acquire the parsing behavior of a different element. When a custom Safelist permits certain raw-text elements, this misparsing can cause content that should remain inert text to be emitted as active markup after serialization, potentially resulting in cross-site scripting. jsoup's built-in Safelists are not affected. This issue is fixed in version 1.23.1.

A flaw was found in jsoup, a Java library for working with HTML. The HTML parser incorrectly handles malformed tag names ending in a control character. When a custom Safelist allows certain raw-text elements, this misparsing can cause content that should be inert to be processed as active markup after serialization. This could allow a remote attacker to achieve cross-site scripting (XSS).

Отчет

This cross-site scripting flaw in jsoup requires a custom Safelist that explicitly allows raw-text elements, which is not a default configuration. Exploitation is limited to applications processing untrusted HTML with such a permissive custom Safelist, reducing the overall risk.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4jsoupFix deferred
Migration Toolkit for Applications 8mta/mta-cli-rhel9Fix deferred
Migration Toolkit for Applications 8mta/mta-java-external-provider-rhel9Fix deferred
OpenShift Developer Tools and Servicesjenkins-2-pluginsFix deferred
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel8Fix deferred
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel9Fix deferred
Red Hat AMQ Broker 7jsoupFix deferred
Red Hat build of Apache Camel - HawtIO 4jsoupFix deferred
Red Hat build of Apicurio Registry 3jsoupFix deferred
Red Hat build of QuarkusjsoupFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1289
https://bugzilla.redhat.com/show_bug.cgi?id=2512346org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
ubuntu
25 дней назад

jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectly handle a malformed tag name ending in a control character, causing the tag to acquire the parsing behavior of a different element. When a custom Safelist permits certain raw-text elements, this misparsing can cause content that should remain inert text to be emitted as active markup after serialization, potentially resulting in cross-site scripting. jsoup's built-in Safelists are not affected. This issue is fixed in version 1.23.1.

CVSS3: 4.7
nvd
25 дней назад

jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectly handle a malformed tag name ending in a control character, causing the tag to acquire the parsing behavior of a different element. When a custom Safelist permits certain raw-text elements, this misparsing can cause content that should remain inert text to be emitted as active markup after serialization, potentially resulting in cross-site scripting. jsoup's built-in Safelists are not affected. This issue is fixed in version 1.23.1.

msrc
21 день назад

jsoup: Cleaner may expose markup with custom raw-text elements

CVSS3: 4.7
debian
25 дней назад

jsoup is a Java library for working with real-world HTML. From 1.14.3 ...

CVSS3: 4.7
github
25 дней назад

jsoup: Cleaner may expose markup with custom raw-text elements

4.7 Medium

CVSS3