SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-75140

HIGH · CVSS 7.5 EPSS 0.53% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability affects jsoup versions up to 1.23.2, allowing remote attackers to exploit an uncontrolled resource consumption issue in the XmlTreeBuilder. By submitting a deeply nested XML document with uniquely-namespaced elements, attackers can cause excessive memory usage, leading to an OutOfMemoryError that can crash the application. Organizations using jsoup should prioritize patching to mitigate the risk of service disruption due to this high-severity flaw.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-75140
Severity
HIGH
CVSS
7.5
EPSS
0.53%

Original NVD Description

jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBuilder that allows remote attackers to exhaust JVM heap memory by supplying a deeply nested XML document with uniquely-namespaced elements. The builder copies the entire inherited namespace map on every start element, causing quadratic time and memory complexity, which attackers can exploit to trigger an OutOfMemoryError and terminate the application.