CyberRota Analysis
AI-GeneratedThe vulnerability affects jsoup versions up to 1.23.2, allowing remote attackers to exploit an uncontrolled resource consumption issue in the XmlTreeBuilder. By submitting a deeply nested XML document with uniquely-namespaced elements, attackers can cause excessive memory usage, leading to an OutOfMemoryError that can crash the application. Organizations using jsoup should prioritize patching to mitigate the risk of service disruption due to this high-severity flaw.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBuilder that allows remote attackers to exhaust JVM heap memory by supplying a deeply nested XML document with uniquely-namespaced elements. The builder copies the entire inherited namespace map on every start element, causing quadratic time and memory complexity, which attackers can exploit to trigger an OutOfMemoryError and terminate the application.