{"id":"CVE-2023-26119","title":"Versions of the package net.sourceforge.htmlunit:htmlunit from 0 and before 3.0.0 are vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage.","summary":"Versions of the package net.sourceforge.htmlunit:htmlunit from 0 and before 3.0.0 are vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage.","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-94"],"vendor":"htmlunit","product":"htmlunit","affected":["htmlunit < 3.0.0"],"patched":["htmlunit 3.0.0"],"published":"2023-04-03","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:17:23.163","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-26119","references":[{"url":"https://github.com/HtmlUnit/htmlunit/commit/641325bbc84702dc9800ec7037aec061ce21956b","label":"report@snyk.io"},{"url":"https://security.snyk.io/vuln/SNYK-JAVA-NETSOURCEFORGEHTMLUNIT-3252500","label":"report@snyk.io"},{"url":"https://siebene.github.io/2022/12/30/HtmlUnit-RCE/","label":"report@snyk.io"},{"url":"https://github.com/HtmlUnit/htmlunit/commit/641325bbc84702dc9800ec7037aec061ce21956b","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.snyk.io/vuln/SNYK-JAVA-NETSOURCEFORGEHTMLUNIT-3252500","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://siebene.github.io/2022/12/30/HtmlUnit-RCE/","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.02513,"epssPercentile":0.84312,"ingestedAt":"2026-10-08T23:16:47.349Z","slug":"CVE-2023-26119","body":"## Overview\n\nVersions of the package net.sourceforge.htmlunit:htmlunit from 0 and before 3.0.0 are vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage.\n\n## Affected\n\n- `htmlunit < 3.0.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `htmlunit 3.0.0`","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.5,"exploitation":0,"ransomware":0},"changes":[]}