---
id: CVE-2021-37714
title: jsoup is a Java library for working with HTML
summary: >-
  jsoup is a Java library for working with HTML. Those using jsoup versions
  prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS
  attacks. If the parser is run on user supplied input, an attacker may supply
  content that c…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-248
  - CWE-835
  - CWE-835
vendor: jsoup
product: jsoup
affected:
  - jsoup < 1.14.2
  - quarkus <= 2.2.3
  - banking_trade_finance = 14.5
  - banking_treasury_management = 14.5
  - business_process_management_suite = 12.2.1.3.0
  - business_process_management_suite = 12.2.1.4.0
  - 'flexcube_universal_banking >= 14.0.0, <= 14.3.0'
  - flexcube_universal_banking = 14.5
  - hospitality_token_proxy_service = 19.2
  - peoplesoft_enterprise_peopletools = 8.58
  - peoplesoft_enterprise_peopletools = 8.59
  - primavera_unifier = 20.12
  - primavera_unifier = 21.12
  - 'retail_customer_management_and_segmentation_foundation >= 17.0, <= 19.0'
  - webcenter_portal = 12.2.1.3.0
  - webcenter_portal = 12.2.1.4.0
  - communications_messaging_server = 8.1
  - management_services_for_element_software_and_netapp_hci
  - financial_services_crime_and_compliance_management_studio = 8.0.8.2.0
  - financial_services_crime_and_compliance_management_studio = 8.0.8.3.0
  - middleware_common_libraries_and_tools = 12.2.1.3.0
  - middleware_common_libraries_and_tools = 12.2.1.4.0
  - stream_analytics < 19.1.0.0.6.4
  - stream_analytics = 19c
patched:
  - jsoup 1.14.2
  - stream_analytics 19.1.0.0.6.4
published: '2021-08-18'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:17:38.687'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-37714'
references:
  - url: 'https://github.com/jhy/jsoup/security/advisories/GHSA-m72m-mhq2-9p6c'
    label: security-advisories@github.com
  - url: 'https://jsoup.org/news/release-1.14.1'
    label: security-advisories@github.com
  - url: 'https://jsoup.org/news/release-1.14.2'
    label: security-advisories@github.com
  - url: >-
      https://lists.apache.org/thread.html/r215009dbf7467a9f6506d0c0024cb36cad30071010e62c9352cfaaf0%40%3Cissues.maven.apache.org%3E
    label: security-advisories@github.com
  - url: >-
      https://lists.apache.org/thread.html/r377b93d79817ce649e9e68b3456e6f499747ef1643fa987b342e082e%40%3Cissues.maven.apache.org%3E
    label: security-advisories@github.com
  - url: >-
      https://lists.apache.org/thread.html/r3d71f18adb78e50f626dde689161ca63d3b7491bd9718fcddfaecba7%40%3Cissues.maven.apache.org%3E
    label: security-advisories@github.com
  - url: >-
      https://lists.apache.org/thread.html/r50e9c9466c592ca9d707a5dea549524d19e3287da08d8392f643960e%40%3Cissues.maven.apache.org%3E
    label: security-advisories@github.com
  - url: >-
      https://lists.apache.org/thread.html/r685c5235235ad0c26e86d0ee987fb802c9675de6081dbf0516464e0b%40%3Cnotifications.james.apache.org%3E
    label: security-advisories@github.com
  - url: >-
      https://lists.apache.org/thread.html/r97404676a5cf591988faedb887d64e278f522adcaa823d89ca69defe%40%3Cnotifications.james.apache.org%3E
    label: security-advisories@github.com
  - url: >-
      https://lists.apache.org/thread.html/rc3354080fc67fb50b45b3c2d12dc4ca2a3c1c78dad3d3ba012c038aa%40%3Cnotifications.james.apache.org%3E
    label: security-advisories@github.com
  - url: 'https://security.netapp.com/advisory/ntap-20220210-0022/'
    label: security-advisories@github.com
  - url: 'https://www.oracle.com/security-alerts/cpuapr2022.html'
    label: security-advisories@github.com
  - url: 'https://www.oracle.com/security-alerts/cpujan2022.html'
    label: security-advisories@github.com
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: security-advisories@github.com
  - url: 'https://github.com/jhy/jsoup/security/advisories/GHSA-m72m-mhq2-9p6c'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://jsoup.org/news/release-1.14.1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://jsoup.org/news/release-1.14.2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r215009dbf7467a9f6506d0c0024cb36cad30071010e62c9352cfaaf0%40%3Cissues.maven.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r377b93d79817ce649e9e68b3456e6f499747ef1643fa987b342e082e%40%3Cissues.maven.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r3d71f18adb78e50f626dde689161ca63d3b7491bd9718fcddfaecba7%40%3Cissues.maven.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r50e9c9466c592ca9d707a5dea549524d19e3287da08d8392f643960e%40%3Cissues.maven.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r685c5235235ad0c26e86d0ee987fb802c9675de6081dbf0516464e0b%40%3Cnotifications.james.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r97404676a5cf591988faedb887d64e278f522adcaa823d89ca69defe%40%3Cnotifications.james.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rc3354080fc67fb50b45b3c2d12dc4ca2a3c1c78dad3d3ba012c038aa%40%3Cnotifications.james.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20220210-0022/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuapr2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujan2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.06689
epssPercentile: 0.93734
ingestedAt: '2026-10-08T22:11:53.741Z'
---

## Overview

jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on user supplied input, an attacker may supply content that causes the parser to get stuck (loop indefinitely until cancelled), to complete more slowly than usual, or to throw an unexpected exception. This effect may support a denial of service attack. The issue is patched in version 1.14.2. There are a few available workarounds. Users may rate limit input parsing, limit the size of inputs based on system resources, and/or implement thread watchdogs to cap and timeout parse runtimes.

## Affected

- `jsoup < 1.14.2`
- `quarkus <= 2.2.3`
- `banking_trade_finance = 14.5`
- `banking_treasury_management = 14.5`
- `business_process_management_suite = 12.2.1.3.0`
- `business_process_management_suite = 12.2.1.4.0`
- `flexcube_universal_banking >= 14.0.0, <= 14.3.0`
- `flexcube_universal_banking = 14.5`
- `hospitality_token_proxy_service = 19.2`
- `peoplesoft_enterprise_peopletools = 8.58`
- `peoplesoft_enterprise_peopletools = 8.59`
- `primavera_unifier = 20.12`
- `primavera_unifier = 21.12`
- `retail_customer_management_and_segmentation_foundation >= 17.0, <= 19.0`
- `webcenter_portal = 12.2.1.3.0`
- `webcenter_portal = 12.2.1.4.0`
- `communications_messaging_server = 8.1`
- `management_services_for_element_software_and_netapp_hci`
- `financial_services_crime_and_compliance_management_studio = 8.0.8.2.0`
- `financial_services_crime_and_compliance_management_studio = 8.0.8.3.0`
- `middleware_common_libraries_and_tools = 12.2.1.3.0`
- `middleware_common_libraries_and_tools = 12.2.1.4.0`
- `stream_analytics < 19.1.0.0.6.4`
- `stream_analytics = 19c`

## Remediation

Upgrade past the affected range:

- `jsoup 1.14.2`
- `stream_analytics 19.1.0.0.6.4`
