Metrics
Affected Vendors & Products
Fri, 21 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jhy
Jhy jsoup |
|
| Vendors & Products |
Jhy
Jhy jsoup |
Fri, 21 Aug 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Aug 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBuilder that allows remote attackers to exhaust JVM heap memory by supplying a deeply nested XML document with uniquely-namespaced elements. The builder copies the entire inherited namespace map on every start element, causing quadratic time and memory complexity, which attackers can exploit to trigger an OutOfMemoryError and terminate the application. | |
| Title | jsoup Uncontrolled Resource Consumption in XmlTreeBuilder | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-21T11:21:02.259Z
Reserved: 2026-08-17T18:39:57.661Z
Link: CVE-2026-75140
Updated: 2026-08-20T17:04:11.821Z
Status : Received
Published: 2026-08-20T16:18:02.030
Modified: 2026-08-20T17:19:41.990
Link: CVE-2026-75140
No data.
OpenCVE Enrichment
Updated: 2026-08-21T13:01:45Z