{"id":"CVE-2022-29577","title":"OWASP AntiSamy before 1.6.7 allows XSS via HTML tag smuggling on STYLE content with crafted input","summary":"OWASP AntiSamy before 1.6.7 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheets (CSS) content. NOTE: this issue exists because of an in…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"antisamy_project","product":"antisamy","affected":["antisamy < 1.6.7","enterprise_manager_base_platform = 13.4.0.0","enterprise_manager_base_platform = 13.5.0.0","weblogic_server = 12.2.1.3.0","weblogic_server = 12.2.1.4.0","weblogic_server = 14.1.1.0.0"],"patched":["antisamy 1.6.7"],"published":"2022-04-21","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:17:20.680","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-29577","references":[{"url":"https://github.com/nahsra/antisamy/commit/32e273507da0e964b58c50fd8a4c94c9d9363af0","label":"cve@mitre.org"},{"url":"https://github.com/nahsra/antisamy/releases/tag/v1.6.7","label":"cve@mitre.org"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"cve@mitre.org"},{"url":"https://github.com/nahsra/antisamy/commit/32e273507da0e964b58c50fd8a4c94c9d9363af0","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/nahsra/antisamy/releases/tag/v1.6.7","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.01328,"epssPercentile":0.70144,"exploits":{"github":1,"githubRepos":["https://github.com/shoucheng3/nahsra__antisamy_CVE-2022-29577_1-6-6-1"],"checkedAt":"2026-10-08T23:17:21.758Z"},"exploitAvailable":true,"ingestedAt":"2026-10-08T23:16:47.341Z","slug":"CVE-2022-29577","body":"## Overview\n\nOWASP AntiSamy before 1.6.7 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheets (CSS) content. NOTE: this issue exists because of an incomplete fix for CVE-2022-28367.\n\n## Affected\n\n- `antisamy < 1.6.7`\n- `enterprise_manager_base_platform = 13.4.0.0`\n- `enterprise_manager_base_platform = 13.5.0.0`\n- `weblogic_server = 12.2.1.3.0`\n- `weblogic_server = 12.2.1.4.0`\n- `weblogic_server = 14.1.1.0.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `antisamy 1.6.7`","depth":"twilight","depthScore":46,"depthScoreParts":{"impact":33.6,"likelihood":0.3,"exploitation":12,"ransomware":0},"changes":[]}