---
id: CVE-2022-29577
title: >-
  OWASP AntiSamy before 1.6.7 allows XSS via HTML tag smuggling on STYLE content
  with crafted input
summary: >-
  OWASP AntiSamy before 1.6.7 allows XSS via HTML tag smuggling on STYLE content
  with crafted input. The output serializer does not properly encode the
  supposed Cascading Style Sheets (CSS) content. NOTE: this issue exists because
  of an in…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: antisamy_project
product: antisamy
affected:
  - antisamy < 1.6.7
  - enterprise_manager_base_platform = 13.4.0.0
  - enterprise_manager_base_platform = 13.5.0.0
  - weblogic_server = 12.2.1.3.0
  - weblogic_server = 12.2.1.4.0
  - weblogic_server = 14.1.1.0.0
patched:
  - antisamy 1.6.7
published: '2022-04-21'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:17:20.680'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-29577'
references:
  - url: >-
      https://github.com/nahsra/antisamy/commit/32e273507da0e964b58c50fd8a4c94c9d9363af0
    label: cve@mitre.org
  - url: 'https://github.com/nahsra/antisamy/releases/tag/v1.6.7'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: cve@mitre.org
  - url: >-
      https://github.com/nahsra/antisamy/commit/32e273507da0e964b58c50fd8a4c94c9d9363af0
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/nahsra/antisamy/releases/tag/v1.6.7'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.01328
epssPercentile: 0.70144
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/shoucheng3/nahsra__antisamy_CVE-2022-29577_1-6-6-1'
  checkedAt: '2026-10-08T23:17:21.758Z'
exploitAvailable: true
ingestedAt: '2026-10-08T23:16:47.341Z'
---

## Overview

OWASP AntiSamy before 1.6.7 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheets (CSS) content. NOTE: this issue exists because of an incomplete fix for CVE-2022-28367.

## Affected

- `antisamy < 1.6.7`
- `enterprise_manager_base_platform = 13.4.0.0`
- `enterprise_manager_base_platform = 13.5.0.0`
- `weblogic_server = 12.2.1.3.0`
- `weblogic_server = 12.2.1.4.0`
- `weblogic_server = 14.1.1.0.0`

## Remediation

Upgrade past the affected range:

- `antisamy 1.6.7`
