---
id: CVE-2026-75140
title: >-
  jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled
  resource consumption vulnerability in XmlTreeBuilder that allows remote
  attackers to exhaust JVM heap memory by supplying a deeply nested XML document
  with uniquely-…
summary: >-
  jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled
  resource consumption vulnerability in XmlTreeBuilder that allows remote
  attackers to exhaust JVM heap memory by supplying a deeply nested XML document
  with uniquely-…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-770
  - CWE-1050
published: '2026-08-20'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T20:02:50.260'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-75140'
references:
  - url: >-
      https://github.com/jhy/jsoup/commit/862ba2f1d48ee95609183dbcfc848c9fd7afc76a
    label: disclosure@vulncheck.com
  - url: 'https://github.com/jhy/jsoup/pull/2556'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/jsoup-uncontrolled-resource-consumption-in-xmltreebuilder
    label: disclosure@vulncheck.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-75140.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-75140'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2520546'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-75140'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-75140'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
epss: 0.0075
epssPercentile: 0.52949
ingestedAt: '2026-09-24T20:51:40.212Z'
vendor: Red Hat
product: Red Hat Enterprise Linux 8
affected:
  - exploit_intelligence
  - migration_toolkit_for_applications 8
  - openshift_developer_tools_and_services
  - enterprise_linux 7
  - enterprise_linux 8
  - enterprise_linux 9
  - jboss_enterprise_application_platform 7
  - openstack_platform_13_queens
  - single_sign_on 7
---

## Overview

jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBuilder that allows remote attackers to exhaust JVM heap memory by supplying a deeply nested XML document with uniquely-namespaced elements. The builder copies the entire inherited namespace map on every start element, causing quadratic time and memory complexity, which attackers can exploit to trigger an OutOfMemoryError and terminate the application.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Important · affected: Exploit Intelligence, Migration Toolkit for Applications 8, OpenShift Developer Tools and Services, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, … · no fix planned: Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat JBoss Enterprise Application Platform 7, Exploit Intelligence, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-75140.json)
