8.7 HIGH
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): None (N)
- Vulnerable System Impact Integrity (VI): None (N)
- Vulnerable System Impact Availability (VA): High (H)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): None (N)
- Modified Vulnerable System Impact Integrity (MVI): None (N)
- Modified Vulnerable System Impact Availability (MVA): High (H)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
Activity log
- Created suggestion
jsoup Uncontrolled Resource Consumption in XmlTreeBuilder
jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBuilder that allows remote attackers to exhaust JVM heap memory by supplying a deeply nested XML document with uniquely-namespaced elements. The builder copies the entire inherited namespace map on every start element, causing quadratic time and memory complexity, which attackers can exploit to trigger an OutOfMemoryError and terminate the application.
References
-
Pull Request issue-tracking
-
Patch Commit patch
-
https://www.vulncheck.com/advisories/jsoup-uncontrolled-resource-consumption-in… third-party-advisory
Affected products
- ==862ba2f1d48ee95609183dbcfc848c9fd7afc76a
- =<1.23.1
Matching in nixpkgs
pkgs.soupault
Tool that helps you create and manage static websites
pkgs.libsoup_3
HTTP client/server library for GNOME
pkgs.libsoup_2_4
None
pkgs.haskellPackages.gi-soup
Libsoup 3.x bindings (compatibility layer)
pkgs.haskellPackages.gi-soup3
Libsoup 3.x bindings
pkgs.ocamlPackages.lambdasoup
Functional HTML scraping and rewriting with CSS in OCaml
pkgs.python313Packages.texsoup
Fault-tolerant Python3 package for searching, navigating, and modifying LaTeX documents
pkgs.python314Packages.texsoup
Fault-tolerant Python3 package for searching, navigating, and modifying LaTeX documents
pkgs.python313Packages.soupsieve
CSS4 selector implementation for Beautiful Soup
pkgs.python314Packages.soupsieve
CSS4 selector implementation for Beautiful Soup
pkgs.haskellPackages.HandsomeSoup
Work with HTML more easily in HXT
pkgs.ocamlPackages_latest.lambdasoup
Functional HTML scraping and rewriting with CSS in OCaml
pkgs.python313Packages.beautifulsoup4
HTML and XML parser
pkgs.python313Packages.mechanicalsoup
Python library for automating interaction with websites
pkgs.python314Packages.beautifulsoup4
HTML and XML parser
pkgs.python314Packages.mechanicalsoup
Python library for automating interaction with websites
pkgs.python313Packages.types-beautifulsoup4
Typing stubs for beautifulsoup4
-
nixos-unstable 4.12.0.20250516
- nixpkgs-unstable 4.12.0.20250516
- nixos-unstable-small 4.12.0.20250516
-
nixos-26.05 4.12.0.20250516
- nixos-26.05-small 4.12.0.20250516
- nixpkgs-26.05-darwin 4.12.0.20250516
pkgs.python314Packages.types-beautifulsoup4
Typing stubs for beautifulsoup4
-
nixos-unstable 4.12.0.20250516
- nixpkgs-unstable 4.12.0.20250516
- nixos-unstable-small 4.12.0.20250516
-
nixos-26.05 4.12.0.20250516
- nixos-26.05-small 4.12.0.20250516
- nixpkgs-26.05-darwin 4.12.0.20250516
Package maintainers
-
@jtojnar Jan Tojnar <jtojnar@gmail.com>
-
@bobby285271 Bobby Rong <rjl931189261@126.com>
-
@nekowinston winston <hey@winston.sh>
-
@theCapypara Marco Köpcke <hello@capypara.de>
-
@thunze Tom Hunze
-
@vbgl Vincent Laporte <Vincent.Laporte@gmail.com>
-
@jgillich Jakob Gillich <jakob@gillich.me>
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>
-
@toastal toastal <toastal+nix@posteo.net>