OutOfMemory Exception by specifically crafted processing instruction in NekoHtml Parser
High severity
GitHub Reviewed
Published
Apr 24, 2022
in
HtmlUnit/htmlunit-neko
•
Updated Jan 27, 2023
Package
Affected versions
< 2.61.0
Patched versions
2.61.0
Description
Published by the National Vulnerability Database
Apr 25, 2022
Published to the GitHub Advisory Database
Apr 26, 2022
Reviewed
Apr 26, 2022
Last updated
Jan 27, 2023
Impact
NekoHtml Parser suffers from a denial of service vulnerability on versions 2.60.0 and below. A specifically crafted input regarding the parsing of processing instructions leads to heap memory consumption. Please update to version 2.61.0.
For more information
If you have any questions or comments about this advisory:
References