CVE-2022-28366

HIGHCVSS 7.5/10EPSS 1.97%

Last modified

CVE-2022-28366 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Certain Neko-related HTML parsers allow a denial of service via crafted Processing Instruction (PI) input that causes excessive heap memory consumption. In particular, this issue exists in HtmlUnit-Neko through 2.26, and is fixed in 2.27. EPSS estimates a 1.97% chance of exploitation in the next 30 days.

Description

Certain Neko-related HTML parsers allow a denial of service via crafted Processing Instruction (PI) input that causes excessive heap memory consumption. In particular, this issue exists in HtmlUnit-Neko through 2.26, and is fixed in 2.27. This issue also exists in CyberNeko HTML through 1.9.22 (also affecting OWASP AntiSamy before 1.6.6), but 1.9.22 is the last version of CyberNeko HTML. NOTE: this may be related to CVE-2022-24839.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
1.97%

77.9th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
Cyberneko Html ProjectCyberneko Html<= 1.9.22
HtmlunitHtmlunit< 2.27
Antisamy ProjectAntisamy< 1.6.6

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-28366?
Certain Neko-related HTML parsers allow a denial of service via crafted Processing Instruction (PI) input that causes excessive heap memory consumption. In particular, this issue exists in HtmlUnit-Neko through 2.26, and is fixed in 2.27. This issue also exists in CyberNeko HTML through 1.9.22 (also affecting OWASP AntiSamy before 1.6.6), but 1.9.22 is the last version of CyberNeko HTML. NOTE: this may be related to CVE-2022-24839.
How severe is CVE-2022-28366?
CVE-2022-28366 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 1.97% probability of exploitation in the next 30 days.
How do I fix CVE-2022-28366?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-28366?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST