CVE-2021-37714High· 7.5▾ Twilightjsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on user supplied input, an attacker may supply content that c…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 1.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
6.7%
jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on user supplied input, an attacker may supply content that causes the parser to get stuck (loop indefinitely until cancelled), to complete more slowly than usual, or to throw an unexpected exception. This effect may support a denial of service attack. The issue is patched in version 1.14.2. There are a few available workarounds. Users may rate limit input parsing, limit the size of inputs based on system resources, and/or implement thread watchdogs to cap and timeout parse runtimes.
jsoup < 1.14.2quarkus <= 2.2.3banking_trade_finance = 14.5banking_treasury_management = 14.5business_process_management_suite = 12.2.1.3.0business_process_management_suite = 12.2.1.4.0flexcube_universal_banking >= 14.0.0, <= 14.3.0flexcube_universal_banking = 14.5hospitality_token_proxy_service = 19.2peoplesoft_enterprise_peopletools = 8.58peoplesoft_enterprise_peopletools = 8.59primavera_unifier = 20.12primavera_unifier = 21.12retail_customer_management_and_segmentation_foundation >= 17.0, <= 19.0webcenter_portal = 12.2.1.3.0webcenter_portal = 12.2.1.4.0communications_messaging_server = 8.1management_services_for_element_software_and_netapp_hcifinancial_services_crime_and_compliance_management_studio = 8.0.8.2.0financial_services_crime_and_compliance_management_studio = 8.0.8.3.0middleware_common_libraries_and_tools = 12.2.1.3.0middleware_common_libraries_and_tools = 12.2.1.4.0stream_analytics < 19.1.0.0.6.4stream_analytics = 19cUpgrade past the affected range:
jsoup 1.14.2stream_analytics 19.1.0.0.6.4Connected by shared product, vendor, weakness, or advisory.
CVE-2021-39140Medium· 6.5XStream is a simple library to serialize objects to XML and back again
CVE-2022-23437Medium· 6.5There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads
CVE-2020-13935High· 7.5The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104
CVE-2015-6748Medium· 6.1Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3.
CVE-2026-86537High· 8.7Uncaught exception, Loop with unreachable exit condition ('infinite loop'), Integer underflow (wrap or wraparound) vulnerability in Apache Thrift D language bindings. This issue affects Apache Thrift: before 0.25.0. Users are recom…
CVE-2026-102511High· 8.5Improper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Apache PLC4X (PLC4Go) allows an attacker able to send UDP datagrams to the discovering host to redirect subsequent connections to…