CVE-2022-28366
Last modified
CVE-2022-28366 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Certain Neko-related HTML parsers allow a denial of service via crafted Processing Instruction (PI) input that causes excessive heap memory consumption. In particular, this issue exists in HtmlUnit-Neko through 2.26, and is fixed in 2.27. EPSS estimates a 1.97% chance of exploitation in the next 30 days.
Description
Certain Neko-related HTML parsers allow a denial of service via crafted Processing Instruction (PI) input that causes excessive heap memory consumption. In particular, this issue exists in HtmlUnit-Neko through 2.26, and is fixed in 2.27. This issue also exists in CyberNeko HTML through 1.9.22 (also affecting OWASP AntiSamy before 1.6.6), but 1.9.22 is the last version of CyberNeko HTML. NOTE: this may be related to CVE-2022-24839.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cyberneko Html Project | Cyberneko Html | <= 1.9.22 |
| Htmlunit | Htmlunit | < 2.27 |
| Antisamy Project | Antisamy | < 1.6.6 |
References
- https://github.com/nahsra/antisamy/releases/tag/v1.6.6Release Notes, Third Party Advisory
- https://search.maven.org/artifact/net.sourceforge.htmlunit/neko-htmlunitRelease Notes, Third Party Advisory
- https://sourceforge.net/projects/htmlunit/files/htmlunit/2.27/Release Notes, Third Party Advisory
- https://github.com/nahsra/antisamy/releases/tag/v1.6.6Release Notes, Third Party Advisory
- https://search.maven.org/artifact/net.sourceforge.htmlunit/neko-htmlunitRelease Notes, Third Party Advisory
- https://sourceforge.net/projects/htmlunit/files/htmlunit/2.27/Release Notes, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-28366?
How severe is CVE-2022-28366?
How do I fix CVE-2022-28366?
Are you affected by CVE-2022-28366?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
